CVE Database /
CVE-2025-68065
CVE · High
CVE-2025-68065 — Hub Core [hub-core] < 6.0.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-68065
|
Hub Core [hub-core] < 6.0.2 |
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') |
High
7.5
|
< 6.0.2
|
6.0.2 |
2025-11-09 |
—
|
CVE-2025-68065
Authenticated users with contributor-level access or higher can exploit a local file inclusion vulnerability in Hub Core plugin versions prior to 5.0.8, allowing them to execute arbitrary PHP code from any server-side file. This flaw enables attackers to circumvent security restrictions and potentially extract sensitive information. The vulnerability also affects files uploaded as "safe" types, such as images.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings