CVE-2025-32298 | Case-Themes CTUsers Plugin up to 1.0.0 on WordPress filename control (EUVD-2025-19279)
A vulnerability, which was classified as problematic, has been found in Case-Themes CTUsers Plugin up to 1.0.0 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is handled as CVE-2025-32298. The attack may be launched remotely. There is no exploit available.