Skip to main content

Threat intelligence

MaxShop <= 3.6.20 - Unauthenticated Local File Inclusion

CVE-2025-69047 · sw_maxshop

Important: Seeing this vulnerability listed does not mean your website is affected. Exposure depends on whether you run Sw_maxshop at a vulnerable version. How SiteRespond intelligence works

Vulnerability
MaxShop <= 3.6.20 - Unauthenticated Local File Inclusion
Affected software
sw_maxshop(Theme)
Affected versions
  • ≤ 3.6.20
Authentication
Unauthenticated
Vulnerability type
Other
Published
30 December 2025
CISA KEV
Not listed in CISA KEV at last catalog refresh
Impact
This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.
Source

Data imported from Wordfence Intelligence (advisory c883c5ab-7bff-48c8-9842-bf51f016981a). Methodology and redistribution notes

Check whether your installed version is affected

SiteRespond Defence matches your installed Sw_maxshop version against this catalog when the Defence plugin is connected to your WordPress site.