Impact
The vulnerability is caused by improper control of the filename used in an include/require statement in PHP, allowing local file inclusion. This weakness can let an attacker read arbitrary files or potentially execute malicious code depending on the included file, thereby compromising data confidentiality and system integrity. The issue is classified as CWE-98.
Affected Systems
The affected product is the ntm Custom Field List Widget Plugin for WordPress, versions up through 1.5.1. No other products or vendors are listed.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity, and the very low EPSS score (<1%) suggests that exploitation is presently unlikely, but still possible. The vulnerability is not listed in CISA KEV. The attack vector is inferred to be a local file inclusion that can be triggered via a crafted HTTP request to the plugin, potentially leading to code execution or information disclosure.
OpenCVE Enrichment
EUVD