Impact
The vulnerability is an improper control of filename for an include/require statement in PHP, allowing an attacker to trigger PHP Local File Inclusion. This flaw is categorized as CWE‑98 and can enable an attacker to read arbitrary files from the server or, in some configurations, execute unintended code. The impact is therefore the potential disclosure of sensitive files or arbitrary code execution on the host, compromising confidentiality, integrity, and availability of the affected WordPress site.
Affected Systems
The affected product is the WordPress Booking and Rental Manager plugin from magepeopleteam, specifically the version family listed as n/a through <= 2.2.8. Users running any supported WordPress installation that has this plugin installed prior to or at version 2.2.8 are susceptible.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity risk. The EPSS score is noted as 1%, indicating a low but non‑negligible likelihood of exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. Attackers would likely exploit this flaw via a crafted request that manipulates the include process, leveraging the plugin’s file inclusion path without proper validation. The attack does not require special privileges beyond the web application context.
OpenCVE Enrichment
EUVD