CVE-2026-25382 | jwsthemes IdealAuto Plugin up to 3.8.6 on WordPress filename control
A vulnerability labeled as critical has been found in jwsthemes IdealAuto Plugin up to 3.8.6 on WordPress. Impacted is an unknown function. Executing a manipulation can lead to improper control of filename for include/require statement in php program ('php remote file inclusion').
The identification of this vulnerability is CVE-2026-25382. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.