References https://nvd.nist.gov/vuln/detail/CVE-2025-3103 https://access.redhat.com/security/cve/cve-2025-3103 https://github.com/advisories/GHSA-cgf8-4346-5g89 https://www.ameeba.com/blog/cve-2025-3103-arbitrary-file-read-vulnerability-in-clever-html5-radio-player-with-history-shoutcast-and-icecast-elementor-widget-addon-plugin-for-wordpress/ https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/elementor_widget_clever_radio_player https://hackhalt.com/threat/cve-2025-3103/ https://strobes.co/vi/cve/CVE-2025-3103/ https://cve.imfht.com/detail/CVE-2025-3103?lang=en https://www.nsfocus.net/vulndb/124230 https://cve.imfht.com/product/CLEVER%20-%20HTML5%20Radio%20Player%20With%20History%20-%20Shoutcast%20and%20Icecast%20-%20Elementor%20Widget%20Addon?lang=en
Related VulnerabilitiesPoCCVE-2026-53629: GLPI - Blind SQL Injection in History Log Filter (LogBleed)Piwigo /ws.php pwg.history.search 未授权访问漏洞(CVE-2026-27833)PoCCVE-2026-27833: Piwigo < 16.3.0 - Unauthenticated Information Disclosure via History APIGradio /proxy 服务器端请求伪造漏洞(CVE-2023-34239)PoCCVE-2026-28414: Gradio - Absolute Path TraversalGradio /static//windows/win.ini 文件读取漏洞 (CVE-2026-28414)PoCgradio-file-redirect: Gradio - Open RedirectKaltura 视频平台 /html5/html5lib/v2.34/simplePhpXMLProxy.php 服务器端请求伪造漏洞PoCsqlite-history-exposure: SQLite History - ExposurePoCpostgres-history-exposure: PostgreSQL History - ExposurePoCnode-repl-history-disclosure: Node.js REPL History DisclosurePoCpython-history-disclosure: Python History File Disclosure