CVE-2025-47670: WordPress Social Login and Register plugin <= 7.6.10 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange WordPress Social Login and Register allows PHP Local File Inclusion. This issue affects WordPress Social Login and Register: from n/a through 7.6.10.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47670?
CVE-2025-47670 has been classified as a high severity vulnerability due to its potential for local file inclusion which can lead to unauthorized access to sensitive files.
How do I fix CVE-2025-47670?
To fix CVE-2025-47670, update your miniOrange WordPress Social Login and Register plugin to version 7.6.11 or later.
What software is affected by CVE-2025-47670?
CVE-2025-47670 affects miniOrange WordPress Social Login and Register versions up to 7.6.10.
What kind of attack can CVE-2025-47670 facilitate?
CVE-2025-47670 can facilitate a local file inclusion (LFI) attack, allowing unauthorized access to files on the server.
Is there a known exploit for CVE-2025-47670?
Yes, proof-of-concept exploits for CVE-2025-47670 have been reported, demonstrating the vulnerability's impact.