Impact
The vulnerability resides in the WordPress Hero Banner Ultimate plugin where an attacker can manipulate the filename used in a PHP include/require statement. Lack of proper validation allows the plugin to read or execute arbitrary files from the server, potentially leading to disclosure of sensitive data or execution of malicious code. The weakness is classified as CWE-98 – Improper Control of Filename for Include/Require Statement.
Affected Systems
The affected product is the Essential Plugin Hero Banner Ultimate, version 1.4.4 and earlier. Any WordPress site that has installed the plugin at a version from the beginning through 1.4.4 is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate to high severity. The EPSS score of less than 1% suggests that the probability of current exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would likely involve submitting a specially crafted web request that triggers the include mechanism; based on the description, it is inferred that the attack could be carried out remotely via an HTTP request to the vulnerable plugin without additional authentication.
OpenCVE Enrichment
EUVD