cleantalk
Vulnerabilities and Security Researches

Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors, CVE-2025-47496

CVE, Research URL

CVE-2025-47496

Published on
May 07, 2025
Research Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PublishPress PublishPress Authors allows PHP Local File Inclusion. This issue affects PublishPress Authors: from n/a through 4.7.5.
Affected versions
Min -, max 4.7.6.
Status
vulnerable