CVE-2025-39470

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Apr 18, 2025
Updated: Apr 21, 2025
CWE ID 35

Summary

CVE-2025-39470 is a newly identified vulnerability affecting the Ivy School plugin by ThimPress. The flaw involves a path traversal issue that enables PHP Local File Inclusion. An attacker can exploit this vulnerability by manipulating the file path to include arbitrary files on the targeted system. This issue puts Ivy School installations from version n/a through 1.6.0 at risk, requiring immediate attention from users to apply the necessary security updates.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share