CVE-2025-28998 | SERPed Plugin up to 4.6 on WordPress filename control (EUVD-2025-19273)
A vulnerability classified as problematic has been found in SERPed Plugin up to 4.6 on WordPress. Affected is an unknown function. The manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is traded as CVE-2025-28998. It is possible to launch the attack remotely. There is no exploit available.