Permalink
CVE-2025-58928
8.1 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): HIGH
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
Activity log
- Created suggestion
WordPress Heart theme <= 1.8 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Heart heart allows PHP Local File Inclusion.This issue affects Heart: from n/a through <= 1.8.
References
Affected products
heart
- =<<= 1.8
Matching in nixpkgs
pkgs.heartbeat7
Lightweight shipper for uptime monitoring
Package maintainers
-
@fadenb Tristan Helmich <tristan.helmich+nixos@gmail.com>
-
@basvandijk Bas van Dijk <v.dijk.bas@gmail.com>
-
@dfithian Daniel Fithian <daniel.m.fithian@gmail.com>
-
@autrimpo Michal Koutenský <michal@koutensky.net>
-
@adda0 David Chocholatý <chocholaty.david@protonmail.com>