Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dzeriho Improved Sale Badges – Free Version improved-sale-badges-free-version allows PHP Local File Inclusion.This issue affects Improved Sale Badges – Free Version: from n/a through <= 1.0.1.
Published: 2025-01-22
Score: 8.1 High
EPSS: 2.2% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, it is inferred that improper control of the filename used in an include/require statement in the dzeriho Improved Sale Badges – Free Version plugin enables PHP Local File Inclusion. An attacker can supply a crafted path to cause the plugin to read and execute arbitrary files on the webserver, which may result in disclosure of sensitive information, modification of site content, or execution of malicious code, thereby compromising confidentiality, integrity, and availability of the WordPress site.

Affected Systems

The vulnerability affects the WordPress plugin Improved Sale Badges – Free Version from the initial release up to and including version 1.0.1. Any WordPress site that has this plugin installed and has not upgraded past version 1.0.1 is potentially impacted.

Risk and Exploitability

Based on the description, it is inferred that the attack vector is a local server path disclosure or manipulation of the include arguments. The CVSS score is 8.1, indicating a high severity. The EPSS score of 1.6% shows a moderate probability of exploitation. The issue is not listed in CISA KEV, but it remains a significant risk for sites that are publicly reachable and are using the affected plugin. Exploitation is likely to occur via a local server path disclosure or manipulation of the include arguments, enabling the attacker to read sensitive files or execute code.

Generated by OpenCVE AI on May 2, 2026 at 05:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Improved Sale Badges – Free Version plugin to version 1.0.2 or later
  • Disable or remove the plugin if it is not required for site functionality
  • Implement file permissions that restrict web server access to sensitive directories, ensuring that local files cannot be read or executed through the plugin

Generated by OpenCVE AI on May 2, 2026 at 05:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3562 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mihajlovic Nenad Improved Sale Badges – Free Version allows PHP Local File Inclusion. This issue affects Improved Sale Badges – Free Version: from n/a through 1.0.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mihajlovic Nenad Improved Sale Badges – Free Version allows PHP Local File Inclusion. This issue affects Improved Sale Badges – Free Version: from n/a through 1.0.1. Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dzeriho Improved Sale Badges – Free Version improved-sale-badges-free-version allows PHP Local File Inclusion.This issue affects Improved Sale Badges – Free Version: from n/a through <= 1.0.1.
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 22 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jan 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mihajlovic Nenad Improved Sale Badges – Free Version allows PHP Local File Inclusion. This issue affects Improved Sale Badges – Free Version: from n/a through 1.0.1.
Title WordPress Improved Sale Badges – Free Version Plugin <= 1.0.1 - Local File Inclusion vulnerability
Weaknesses CWE-98
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-11T23:05:43.667Z

Reserved: 2025-01-16T11:32:45.573Z

Link: CVE-2025-23949

cve-icon Vulnrichment

Updated: 2025-01-22T15:24:28.911Z

cve-icon NVD

Status : Deferred

Published: 2025-01-22T15:15:26.527

Modified: 2026-04-23T15:24:50.460

Link: CVE-2025-23949

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T05:45:20Z

Weaknesses
  • CWE-98

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')