CVE-2025-49271 HIGH

CVE-2025-49271: WordPress GravityWP - Merge Tags <= 1.4.4 - Local File Inclusion Vulnerability

Vendor Gravitywp
Product GravityWP - Merge Tags
Weakness CWE-98 · PHP file inclusion
Published August 14, 2025
Last update May 12, 2026

CVSS base score

7.5/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in GravityWP GravityWP - Merge Tags gravitywp-merge-tags allows PHP Local File Inclusion.This issue affects GravityWP - Merge Tags: from n/a through <= 1.4.4.

Explanation of Vulnerability in Simple Terms

02Summary

GravityWP Merge Tags versions 1.4.4 and earlier contain a vulnerability that allows an attacker to execute arbitrary code on the site. The attack requires user interaction—typically a site administrator must visit a malicious link or page. An attacker with no prior authentication can exploit this to gain full control of the WordPress installation.

What an attacker can do

03Attacker Capabilities

Run arbitrary code on the site and take full control of the WordPress installation.

Potential impact on your site

04Site Impact

Complete compromise of your WordPress site, including data theft, malware installation, and loss of site control.

Conditions required to exploit

05Prerequisites

An authenticated admin or site user must visit a malicious link or page crafted by the attacker.

Key dates

06Disclosure timeline

August 14, 2025 CVE published
May 12, 2026 Record updated