CVE-2025-58955 | designervily Karzo Plugin up to 2.6 on WordPress filename control
A vulnerability marked as critical has been reported in designervily Karzo Plugin up to 2.6 on WordPress. The affected element is an unknown function. Performing manipulation results in improper control of filename for include/require statement in php program (‘php remote file inclusion’).
This vulnerability is known as CVE-2025-58955. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More