CVE-2025-22656

Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) vulnerability in Oscar Alvarez Cookie Monster allows PHP Local File Inclusion. This issue affects Cookie Monster: from n/a through 1.2.2.

More information : https://patchstack.com/database/wordpress/plugin/cookie-monster/vulnerability/wordpress-cookie-monster-plugin-1-2-2-local-file-inclusion-vulnerability?_s_id=cve