CVE-2025-39570

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Apr 16, 2025
CWE ID 98

Summary

CVE-2025-39570 is a filename manipulation vulnerability affecting the Lomu WPCOM Member plugin for WordPress. It allows an attacker to perform PHP Local File Inclusion by exploiting improper control over include/require statements. This vulnerability, classified as a 'PHP Remote File Inclusion' issue, can be exploited to access sensitive files on the affected system. The issue affects WPCOM Member versions from n/a through 1.7.7. Successful exploitation could lead to unauthorized access or data theft. System administrators are advised to update to the latest version of WPCOM Member to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share