What the vulnerability does
01Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cedcommerce Product Lister for eBay product-lister-ebay allows PHP Local File Inclusion.This issue affects Product Lister for eBay: from n/a through <= 2.0.9.
Explanation of Vulnerability in Simple Terms
02Summary
Product Lister for eBay versions up to 2.0.9 contain a vulnerability that allows an attacker to read sensitive data, modify site content, or disrupt service availability. The attack requires the victim to visit a malicious link or page. No authentication is needed. The vulnerability stems from improper input handling (CWE-98).
What an attacker can do
03Attacker Capabilities
Read sensitive data, modify site content, or disrupt service by tricking a user into visiting a malicious link.
Potential impact on your site
04Site Impact
Site data and content can be compromised; users may experience service disruption if the plugin is actively used.
Conditions required to exploit
05Prerequisites
Victim must click a malicious link or visit an attacker-controlled page; no login required.
Key dates
06Disclosure timeline
April 24, 2025
CVE published
April 28, 2026
Record updated