CVE-2025-30849: WordPress Essential Real Estate plugin <= 5.2.0 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in g5theme Essential Real Estate essential-real-estate allows PHP Local File Inclusion.This issue affects Essential Real Estate: from n/a through <= 5.2.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30849?
CVE-2025-30849 is classified as a high severity vulnerability due to its potential for local file inclusion attacks.
How do I fix CVE-2025-30849?
To fix CVE-2025-30849, update the Essential Real Estate plugin to version 5.2.1 or later.
What versions of Essential Real Estate are affected by CVE-2025-30849?
CVE-2025-30849 affects all versions of Essential Real Estate up to and including 5.2.0.
What types of attacks can be executed using CVE-2025-30849?
CVE-2025-30849 allows attackers to execute local file inclusion attacks, potentially leading to unauthorized access to sensitive files.
Who is affected by CVE-2025-30849?
Users of the g5theme Essential Real Estate plugin and WordPress Essential Real Estate plugin versions up to 5.2.0 are vulnerable to CVE-2025-30849.