CVE-2025-32921
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2025-32921 is a filename manipulation vulnerability affecting WPoperation Arrival, a PHP program. The flaw, classified as a Local File Inclusion vulnerability, enables an attacker to include arbitrary local files on a vulnerable system. This issue arises due to improper control of filenames in the include/require statements within WPoperation Arrival, versions from n/a through 1.4.5. Successful exploitation of this vulnerability could lead to data exposure or arbitrary code execution with the same privileges as the web application. It's essential for users to update their WPoperation Arrival installation to a patched version promptly to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.