CVE-2025-47531

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Xylus Themes XT Event Widget for Social Events allows PHP Local File Inclusion. This issue affects XT Event Widget for Social Events: from n/a through 1.1.7.
Configurations

Configuration 1 (hide)

cpe:2.3:a:xylusthemes:xt_event_widget_for_social_events:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2025-05-07 15:16

Updated : 2026-01-12 14:49


NVD link : CVE-2025-47531

Mitre link : CVE-2025-47531

CVE.ORG link : CVE-2025-47531


JSON object : View

Products Affected

xylusthemes

  • xt_event_widget_for_social_events
CWE
CWE-98

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')