cleantalk
Vulnerabilities and Security Researches

Premium Addons for KingComposer, CVE-2025-49036

CVE, Research URL

CVE-2025-49036

Published on
Aug 14, 2025
Research Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in octagonwebstudio Premium Addons for KingComposer allows PHP Local File Inclusion. This issue affects Premium Addons for KingComposer: from n/a through 1.1.1.
Affected versions
Min -, max 1.1.1.
Status
vulnerable