CVE-2025-9048 | wptobe-memberships Plugin up to 3.4.2 on WordPress del_img_ajax_call file inclusion
A vulnerability, which was classified as problematic, has been found in wptobe-memberships Plugin up to 3.4.2 on WordPress. Affected by this vulnerability is the function del_img_ajax_call. Performing manipulation results in file inclusion.
This vulnerability is cataloged as CVE-2025-9048. It is possible to initiate the attack remotely. There is no exploit available.