CVE-2025-58928 | axiomthemes Heart Plugin up to 1.8 on WordPress filename control
A vulnerability marked as critical has been reported in axiomthemes Heart Plugin up to 1.8 on WordPress. Affected is an unknown function. Performing manipulation results in improper control of filename for include/require statement in php program (‘php remote file inclusion’).
This vulnerability is known as CVE-2025-58928. Remote exploitation of the attack is possible. No exploit is available.VulDB Recent EntriesRead More