CVE-2025-31016

Published Mar 31, 2025

Last updated 4 days ago

Overview

Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Crocoblock JetWooBuilder allows PHP Local File Inclusion.This issue affects JetWooBuilder: from n/a through 2.1.18.
Source
audit@patchstack.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.5
Impact score
5.9
Exploitability score
1.6
Vector string
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

audit@patchstack.com
CWE-98

Social media

Hype score
Not currently trending
  1. 🚨 CVE-2025-31016 🔴 HIGH (7.5) 🏢 Crocoblock - JetWooBuilder 🏗️ Unknown Version 🔗 https://t.co/CkjTywmLAw #CyberCron #VulnAlert #InfoSec https://t.co/tgzUnTMFBQ

    @cybercronai

    31 Mar 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. High Severity CVE *CVE-2025-31016* Score: 7.5/10 Details: https://t.co/WL9pVxPjyL Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Crocoblock JetWooBuilder allows PHP Local File

    @AyushInfo57268

    31 Mar 2025

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. New post from https://t.co/uXvPWJy6tj (CVE-2025-31016 | JetWooBuilder Plugin up to 2.1.18 on WordPress filename control) has been published on https://t.co/Zx8NY9XHB2

    @WolfgangSesin

    31 Mar 2025

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. High Severity CVE *CVE-2025-31016* Score: 7.5/10 Details: https://t.co/WL9pVxPjyL Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound JetWooBuilder allows PHP Local File I

    @AyushInfo57268

    31 Mar 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-31016 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound JetWooBuilder allows PHP Local File … https://t.co/4nEiDqVH8y

    @CVEnew

    31 Mar 2025

    366 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. High Severity CVE *CVE-2025-31016* Score: 7.5/10 Details: https://t.co/WL9pVxOLJd Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound JetWooBuilder allows PHP Local File I

    @AyushInfo57268

    31 Mar 2025

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes