Known CVE
WordPress Formality Plugin <= 1.5.9 - Local File Inclusion
Michele Giorgi Formality <= 1.5.9 contains a file inclusion vulnerability caused by improper control of filename in include/require statements, letting attackers include local files, exploit requires crafted input.
CVE-2025-48157
Critical2025CVSS 9.8CWE-98
cve2025 · wordpress · wp · wp-plugin · formality · lfi · authenticated
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website