Impact
The vulnerability is a local file inclusion flaw where the Notifications for Forms & WordPress Actions WordPress plugin fails to validate a user‑supplied value before constructing a server‑side file inclusion path. This flaw allows an authenticated user with subscriber‑level permissions or higher to specify a local PHP file that will be included and executed on the server. The result is that such a user can run arbitrary PHP code, effectively gaining remote code execution over the application’s hosting environment.
Affected Systems
Any WordPress site that has the Notifications for Forms & WordPress Actions plugin installed at a version earlier than 2.6 is vulnerable. The flaw only applies if the site has users granted subscriber‑level access or higher, so sites without such user roles are not affected by this specific vulnerability.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5, indicating a high severity. The EPSS score is listed as less than 1%, reflecting a very low but non‑zero probability of exploitation in the current threat landscape. It is not listed in the CISA KEV catalog. Because the flaw requires legitimate subscriber‑level authentication, an attacker would need to compromise credentials or otherwise gain appropriate access before being able to exploit the inclusion of arbitrary local files and achieve code execution.
OpenCVE Enrichment