CVE-2025-39452

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 17, 2025
CWE ID 98

Summary

CVE-2025-39452 is a vulnerability affecting Themewinter WPCafe from versions n/a through 2.2.32. This issue involves improper control of filename for include/require statements in PHP, leading to a Local File Inclusion (LFI) vulnerability. An attacker can exploit this flaw to access and run arbitrary local files, potentially leading to server compromise or data exposure. The PHP Remote File Inclusion technique is used in this attack. It's crucial for users to update their Themewinter WPCafe installation to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share