Permalink
CVE-2025-54003
9.8 CRITICAL
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
WordPress Depot theme <= 1.16 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Depot depot allows PHP Local File Inclusion.This issue affects Depot: from n/a through <= 1.16.
References
Affected products
depot
- =<<= 1.16
Matching in nixpkgs
pkgs.depotdownloader
Steam depot downloader utilizing the SteamKit2 library
pkgs.python312Packages.filedepot
Toolkit for storing files and attachments in web applications
Package maintainers
-
@babbaj babbaj <babbaj45@gmail.com>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>