CVE-2025-54028
7.5Saleswonder Team · Tobias CF7 WOW Styler
The Tobias CF7 WOW Styler plugin for WordPress contains a Local File Inclusion vulnerability due to improper handling of filenames in include statements, potentially allowing unauthorized file access.
Executive summary
The Tobias CF7 WOW Styler plugin contains a critical local file inclusion vulnerability that could allow an attacker to read sensitive files or execute arbitrary code on the host server.
Vulnerability
This vulnerability is a PHP Local File Inclusion flaw (CWE-98) occurring within the plugin. An unauthenticated attacker could leverage this issue to include unintended files, potentially leading to full system compromise depending on the server environment.
Business impact
Successful exploitation of this vulnerability could lead to the exposure of sensitive configuration files, database credentials, or other proprietary data stored on the web server. With a CVSS score of 7.5, this represents a significant risk to the confidentiality, integrity, and availability of the WordPress environment and the underlying infrastructure.
Remediation
Immediate Action: Since a specific patch version is currently unknown, users should immediately deactivate and uninstall the Tobias CF7 WOW Styler plugin until a vendor-supplied update is confirmed available.
Proactive Monitoring: Security teams should review web server access logs for anomalous requests containing path traversal sequences or attempts to access system files like etc/passwd.
Compensating Controls: Deploy a Web Application Firewall (WAF) rule designed to block requests containing directory traversal characters or suspicious file inclusion patterns directed at the plugin directory.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for complete system compromise, organizations currently running the Tobias CF7 WOW Styler plugin should treat this vulnerability with high urgency. Prioritize the removal of the affected software and monitor the environment for any signs of unauthorized access or file manipulation until the vendor releases a verified fix.
More Saleswonder Team CVEs
Sources
Originally found and disclosed by LVT-tholv2k | Patchstack Bug Bounty Program, per the CVE Program record.