CVE-2025-26933 - CERT CVE
ID CVE-2025-26933
Sažetak Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nitin Prakash WC Place Order Without Payment allows PHP Local File Inclusion. This issue affects WC Place Order Without Payment: from n/a through 2.6.7.
Reference
CVSS
Base: 7.5
Impact: 5.9
Exploitability:1.6
Pristup
VektorSloženostAutentikacija
NETWORK HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH HIGH
CVSS vektor CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Zadnje važnije ažuriranje 10-03-2025 - 15:15
Objavljeno 10-03-2025 - 15:15