Impact
WordPress IMDb Profile Widget 1.0.8 contains a local file inclusion flaw in pic.php that permits attackers to supply directory traversal sequences through the URL parameter. The vulnerability allows unauthenticated users to read arbitrary files on the server, enabling disclosure of sensitive data such as wp-config.php with database credentials.
Affected Systems
The affected product is the IMDb Profile Widget plugin for WordPress, version 1.0.8 developed by Henrique Dias. No further version details are provided, so all installations of this specific version are vulnerable.
Risk and Exploitability
With a CVSS score of 6.9, the flaw presents moderate risk. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited documented exploitation but still exploitable in any environment where the plugin is installed. Attackers need only craft a GET request to pic.php with a path traversal sequence; no authentication is required, making the attack straightforward and potentially widespread across affected WordPress sites.
OpenCVE Enrichment