CVE-2025-3103
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Apr 19, 2025
Updated: Apr 21, 2025
CWE ID 73
Summary
CVE-2025-3103 is a vulnerability affecting the CLEVER - HTML5 Radio Player With History plugin for WordPress. The 'history.php' file in all versions up to 2.4 of this addon, which is used for Shoutcast and Icecast functionality, lacks adequate file path validation. Consequently, unauthenticated attackers can exploit this weakness to read arbitrary files on the compromised site's server, potentially gaining access to sensitive information, including database credentials. The patch released in version 2.4 provides partial mitigation to this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.