cleantalk
Vulnerabilities and Security Researches

XT Event Widget for Social Events, CVE-2025-47531

CVE, Research URL

CVE-2025-47531

Published on
May 07, 2025
Research Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Xylus Themes XT Event Widget for Social Events allows PHP Local File Inclusion. This issue affects XT Event Widget for Social Events: from n/a through 1.1.7.
Affected versions
Min -, max 1.1.8.
Status
vulnerable