CVE-2025-49271

Publication date

2025-08-14 10:34:09

Family

Patchstack

State

PUBLISHED

Description

Improper Control of Filename for Include/Require Statement in PHP Program (PHP Remote File Inclusion) vulnerability in GravityWP GravityWP - Merge Tags allows PHP Local File Inclusion. This issue affects GravityWP - Merge Tags: from n/a through 1.4.4.