CVE-2025-22656
Published: 18 February 2025
Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Oscar Alvarez Cookie Monster cookie-monster allows PHP Local File Inclusion.This issue affects Cookie Monster: from n/a through <= 1.2.2.
Security Summary
CVE-2025-22656 is an Improper Control of Filename for Include/Require Statement vulnerability, classified as PHP Remote File Inclusion but enabling PHP Local File Inclusion, in the Cookie Monster WordPress plugin by Oscar Alvarez. The issue affects versions from n/a through 1.2.2.
An unauthenticated attacker (PR:N) can exploit this vulnerability remotely over the network (AV:N) with high attack complexity (AC:H) and no user interaction (UI:N), potentially achieving high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H) within unchanged scope (S:U). The vulnerability carries a CVSS 3.1 base score of 8.1 and maps to CWE-98.
Patchstack provides details on this local file inclusion vulnerability in the Cookie Monster WordPress plugin version 1.2.2 via their database advisory.
Details
- CWE(s)