Impact
An improper control of the filename used in PHP include/require statements in the wpWax Post Grid, Slider & Carousel Ultimate plugin allows an attacker to perform local file inclusion. The flaw enables an attacker to read arbitrary local files on the web server and, under certain circumstances, execute code by including files that contain PHP code. This can lead to disclosure of sensitive data, manipulation of site content, or the execution of malicious code, thereby compromising confidentiality, integrity, and availability of the affected WordPress site.
Affected Systems
The vulnerability affects the WordPress plugin wpWax Post Grid, Slider & Carousel Ultimate – any release from the earliest available version through version 1.6.10 is vulnerable. Site owners who have installed this plugin in any of those versions are at risk. The vulnerability is tied to the plugin’s shortcode, Gutenberg block, and Elementor widget interfaces, which are commonly used by site editors and administrators.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity impact. The EPSS score of less than 1% suggests a very low current likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The description does not explicitly state the attack vector, but it is inferred that an attacker could send crafted requests that trigger the plugin’s include logic via publicly accessible shortcode or widget parameters, as indicated by the lack of authentication requirements. Thus a publicly reachable vector is likely.
OpenCVE Enrichment
EUVD