CVE · High

CVE-2025-60240 — AnyComment [anycomment] <= 0.3.6 (unfixed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-60240 AnyComment [anycomment] <= 0.3.6 (unfixed) Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') High 7.5 < 0.3.6 0.3.6 2025-07-12

CVE-2025-60240

The AnyComment plugin for WordPress is susceptible to Local File Inclusion vulnerabilities up to version 0.3.6. Attackers without authentication can exploit this to include and run arbitrary PHP files, potentially leading to the execution of malicious code and unauthorized access to sensitive data.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.