CVE-2025-39507
HIGHNasaTheme Nasa Core < 6.4.4 - PHP Local File Inclusion
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-39507. PoCs published by TheCyberFairy.
AI-analyzed exploit summary This is a detailed writeup documenting a Tier 1 SOC analyst's investigation into CVE-2025-39507, a Local File Inclusion (LFI) vulnerability in the WordPress Nasa Core plugin. It includes background on the CVE, investigation steps, and escalation documentation.
Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NasaTheme Nasa Core nasa-core allows PHP Local File Inclusion.This issue affects Nasa Core: from n/a through < 6.4.4.
Exploits (1)
This is a detailed writeup documenting a Tier 1 SOC analyst's investigation into CVE-2025-39507, a Local File Inclusion (LFI) vulnerability in the WordPress Nasa Core plugin. It includes background on the CVE, investigation steps, and escalation documentation.
References (2)
Scores
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H