CVE-2025-39387
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 98
Summary
CVE-2025-39387 is a filename vulnerability affecting WPoperation Opstore versions 1.4.5 and below. The issue arises from improper control of filenames in PHP include/require statements, leading to a Local File Inclusion (LFI) vulnerability. An attacker can exploit this flaw to access and potentially modify sensitive data on the affected system, posing a significant security risk. This PHP Remote File Inclusion (RFI) vulnerability should be addressed promptly by updating to the latest, secure version of WPoperation Opstore.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.