CVE-2025-32156
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 98
Summary
CVE-2025-32156 is a filename control vulnerability affecting the Just Post Preview Widget by Alex Prokopenko and JustCoded. This issue permits Local File Inclusion in PHP, enabling an attacker to potentially gain unauthorized access to sensitive files by manipulating the include/require statement. The vulnerability exists in versions of the plugin from n/a through 1.1.1. This flaw can lead to significant security risks if exploited, making it crucial for users to update their plugin to a patched version as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.