WPB Category Slider for WooCommerce <= 1.71 - Authenticated (Contributor+) Local File Inclusion
high
The WPB Category Slider for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.71. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP...
- CVSS:
- 7.5
- Affected:
- up to 1.71
- Fix:
- No patched version reported
- Disclosed:
- Jun 27, 2025
CVE-2025-53281 on NVD →
WPB Category Slider for WooCommerce – Product Categories Carousel Slider & Grid with Icon and Images [wpb-woocommerce-category-slider] <= 1.71 (unfixed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WPBean WPB Category Slider for WooCommerce allows PHP Local File Inclusion. This issue affects WPB Category Slider for WooCommerce: from n/a through 1.71.
- Affected:
- up to 1.71
- Fix:
- No patched version reported
- Disclosed:
- Jun 27, 2025
CVE-2025-53281 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database