CVE · High

CVE-2025-68065 — Hub Core [hub-core] < 6.0.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-68065 Hub Core [hub-core] < 6.0.2 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') High 7.5 < 6.0.2 6.0.2 2025-11-09

CVE-2025-68065

Authenticated users with contributor-level access or higher can exploit a local file inclusion vulnerability in Hub Core plugin versions prior to 5.0.8, allowing them to execute arbitrary PHP code from any server-side file. This flaw enables attackers to circumvent security restrictions and potentially extract sensitive information. The vulnerability also affects files uploaded as "safe" types, such as images.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.