CVE-2025-39470
CVSS 3.1 Score 8.1 of 10 (high)
Details
Published Apr 18, 2025
Updated: Apr 21, 2025
CWE ID 35
Summary
CVE-2025-39470 is a newly identified vulnerability affecting the Ivy School plugin by ThimPress. The flaw involves a path traversal issue that enables PHP Local File Inclusion. An attacker can exploit this vulnerability by manipulating the file path to include arbitrary files on the targeted system. This issue puts Ivy School installations from version n/a through 1.6.0 at risk, requiring immediate attention from users to apply the necessary security updates.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.