Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AddonMaster Post Grid Master allows PHP Local File Inclusion. This issue affects Post Grid Master: from n/a through 3.4.12.
Fixes

Solution

Update the WordPress Post Grid Master wordpress plugin to the latest available version (at least 3.4.13).


Workaround

No workaround given by the vendor.

History

Mon, 09 Jun 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Addonmaster
Addonmaster post Grid Master
Weaknesses CWE-706
CPEs cpe:2.3:a:addonmaster:post_grid_master:*:*:*:*:*:wordpress:*:*
Vendors & Products Addonmaster
Addonmaster post Grid Master

Wed, 12 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jan 2025 17:30:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AddonMaster Post Grid Master allows PHP Local File Inclusion. This issue affects Post Grid Master: from n/a through 3.4.12.
Title WordPress Post Grid Master plugin <= 3.4.12 - Local File Inclusion vulnerability
Weaknesses CWE-98
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2025-02-12T20:01:16.268Z

Reserved: 2025-01-23T14:52:51.691Z

Link: CVE-2025-24733

cve-icon Vulnrichment

Updated: 2025-02-12T19:54:44.578Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-24T18:15:47.697

Modified: 2025-06-09T18:56:58.550

Link: CVE-2025-24733

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.