Impact
The VG PostCarousel WordPress plugin contains improper control over filenames used in PHP include/require statements, which permits local file inclusion. An attacker who can influence the filename parameter may read arbitrary files from the server, potentially exposing sensitive data or enabling further exploitation such as remote code execution.
Affected Systems
The vulnerability affects all releases of vinagecko VG PostCarousel up to and including version 1.1. Versions thereafter are considered unaffected.
Risk and Exploitability
The CVSS score of 7.5 reflects a high severity while the EPSS score of less than 1% indicates low but non‑zero exploitation probability. The flaw is not listed in the CISA KEV catalog and no public exploits have been documented. The likely attack vector is a local or crafted request that triggers the vulnerable include/require logic, making the risk contingent on the attacker’s ability to influence file names.
OpenCVE Enrichment
EUVD