CVE-2025-67936 | Mikado-Themes Curly Plugin up to 3.3 on WordPress filename control
A vulnerability categorized as critical has been discovered in Mikado-Themes Curly Plugin up to 3.3 on WordPress. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to improper control of filename for include/require statement in php program ('php remote file inclusion').
The identification of this vulnerability is CVE-2025-67936. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.