Impact
Improper control of the filename used in PHP include/require statements in the RealMag777 HUSKY WooCommerce Products Filter plugin allows attackers to perform local file inclusion. By manipulating the inclusion logic, an attacker can read arbitrary files on the server or potentially execute code if PHP files are included. The vulnerability is classified as CWE-98 and carries a high-level severity on the CVSS scale.
Affected Systems
RealMag777’s HUSKY WooCommerce Products Filter plugin for WordPress, affecting all releases through version 1.3.6.4.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity impact, while the EPSS score of 1% suggests a currently low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack vector relies on manipulating a plugin-controlled path parameter via a web request, so any exposed plugin functionality could be abused under the right conditions.
OpenCVE Enrichment
EUVD