Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 |
Mon, 20 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Wed, 15 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 15 Oct 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The BlindMatrix e-Commerce WordPress plugin before 3.1 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users, such as contributors, to perform LFI attacks. | |
| Title | BlindMatrix e-Commerce < 3.1 - Contributor+ LFI | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-01-09T20:19:45.713Z
Reserved: 2025-09-13T19:50:18.761Z
Link: CVE-2025-10406
Updated: 2025-10-15T13:19:54.188Z
Status : Deferred
Published: 2025-10-15T06:15:34.317
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-10406
No data.
OpenCVE Enrichment
Updated: 2025-10-20T13:27:11Z