{"id":"CVE-2025-10406","title":"The BlindMatrix e-Commerce WordPress plugin before 3.1 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users, such as contributors, to perform LFI a…","summary":"The BlindMatrix e-Commerce WordPress plugin before 3.1 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users, such as contributors, to perform LFI a…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N","cwe":["CWE-22"],"published":"2025-10-15","updated":"2026-10-08","sourceUpdated":"2026-10-08T12:10:00.217","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-10406","references":[{"url":"https://wpscan.com/vulnerability/d8bdd2d4-c03c-4e7f-9c8a-6efc010311b6/","label":"contact@wpscan.com"}],"tags":["nvd"],"epss":0.00261,"epssPercentile":0.16381,"ingestedAt":"2026-10-08T12:39:48.733Z","slug":"CVE-2025-10406","body":"## Overview\n\nThe BlindMatrix e-Commerce WordPress plugin before 3.1 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users, such as contributors, to perform LFI attacks.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}