Untriaged
Permalink
CVE-2025-60053
8.2 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): LOW
- Availability impact (A): NONE
WordPress MaxCube theme <= 1.3.1 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes MaxCube maxcube allows PHP Local File Inclusion.This issue affects MaxCube: from n/a through <= 1.3.1.
References
Affected products
maxcube
- =<<= 1.3.1
Matching in nixpkgs
pkgs.python311Packages.maxcube-api
eQ-3/ELV MAX! Cube Python API
pkgs.python312Packages.maxcube-api
eQ-3/ELV MAX! Cube Python API
pkgs.python313Packages.maxcube-api
eQ-3/ELV MAX! Cube Python API
Package maintainers
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@Mic92 Jörg Thalheim <joerg@thalheim.io>
-
@mweinelt Martin Weinelt <hexa@darmstadt.ccc.de>