CVE-2025-31340
A improper control of filename for include/require statement in PHP program vulnerability in the retrieve course Information function of Wisdom Master Pro versions 5.0 through 5.2 allows remote attackers to perform arbitrary system commands by running a malicious file.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H
- EPSS probability
- 0.46%
- CWE
- CWE-98
- Published
- 2025-04-17
- Last modified
- 2026-03-12
Affected products
- SUNNET Technology Co., Ltd. Wisdom Master Pro
Weakness type
Related vulnerabilities
- CVE-2026-87927 — MaxSite CMS through 109.6 Local File Inclusion via ajax dispatcher
- CVE-2026-15667 — Eventin <= 4.1.22 - Authenticated (Contirbutor+) Local File Inclusion via 'event_layout' Parameter
- CVE-2026-15406 — Eventin <= 4.1.22 - Authenticated (Custom+) Local File Inclusion via 'event_layout' Parameter
- CVE-2026-11613 — Divi Ajax Filter <= 5.1.2 - Unauthenticated Local File Inclusion via 'custom_loop_template' Parameter
- CVE-2026-78566 — The Shuffle theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and...
- CVE-2026-78562 — The Verdure Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to,...
- CVE-2026-78478 — Måne <= 1.7 - Unauthenticated Local File Inclusion
- CVE-2026-14280 — Events Manager <= 7.3.7.4 - Authenticated (Administrator+) Local File Inclusion via 'dbem_data[updates]' Array Keys