CVE Database
/

CVE-2025-10723

Back to search

CVE-2025-10723

Published: Oct 24, 2025

Modified: Jan 9, 2026

PUBLISHED

Description

The PixelYourSite WordPress plugin before 11.1.2 does not validate some URL parameters before using them to generate paths passed to function/s, allowing any admins to perform LFI attacks

VendorProductVersions

Unknown

PixelYourSite

affected
0 - < 11.1.2

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now