CVE-2026-25380 | jwsthemes Feedy Plugin up to 2.1.5 on WordPress filename control
A vulnerability, which was classified as critical, was found in jwsthemes Feedy Plugin up to 2.1.5 on WordPress. The impacted element is an unknown function. The manipulation results in improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is known as CVE-2026-25380. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.