Cyber Posture

CVE-2025-22656

High

Published: 18 February 2025

Published
18 February 2025
Modified
23 April 2026
KEV Added
Patch
CVSS Score 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0113 78.4th percentile
Risk Priority 17 60% EPSS · 20% KEV · 20% CVSS

Description

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Oscar Alvarez Cookie Monster cookie-monster allows PHP Local File Inclusion.This issue affects Cookie Monster: from n/a through <= 1.2.2.

Security Summary

CVE-2025-22656 is an Improper Control of Filename for Include/Require Statement vulnerability, classified as PHP Remote File Inclusion but enabling PHP Local File Inclusion, in the Cookie Monster WordPress plugin by Oscar Alvarez. The issue affects versions from n/a through 1.2.2.

An unauthenticated attacker (PR:N) can exploit this vulnerability remotely over the network (AV:N) with high attack complexity (AC:H) and no user interaction (UI:N), potentially achieving high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H) within unchanged scope (S:U). The vulnerability carries a CVSS 3.1 base score of 8.1 and maps to CWE-98.

Patchstack provides details on this local file inclusion vulnerability in the Cookie Monster WordPress plugin version 1.2.2 via their database advisory.

Details

CWE(s)
CWE-98

References