CVE-2025-39360
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2025-39360 is a filename vulnerability affecting the Grace Mag theme for PHP, from version n/a through 1.1.5. This issue, classified as a PHP Remote File Inclusion (RFI) vulnerability, allows an attacker to include local files on a vulnerable system by manipulating the include/require statement. The improper control of filenames in this context poses a significant security risk, as it may lead to unauthorized file access or execution of arbitrary code. Successful exploitation of this vulnerability could potentially enable attackers to gain unauthorized access or perform actions with elevated privileges on the affected system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.