CVE Database /
CVE-2025-60240
CVE · High
CVE-2025-60240 — AnyComment [anycomment] <= 0.3.6 (unfixed)
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-60240
|
AnyComment [anycomment] <= 0.3.6 (unfixed) |
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') |
High
7.5
|
< 0.3.6
|
0.3.6 |
2025-07-12 |
—
|
CVE-2025-60240
The AnyComment plugin for WordPress is susceptible to Local File Inclusion vulnerabilities up to version 0.3.6. Attackers without authentication can exploit this to include and run arbitrary PHP files, potentially leading to the execution of malicious code and unauthorized access to sensitive data.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings