Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in HT Plugins WishSuite wishsuite allows PHP Local File Inclusion.This issue affects WishSuite: from n/a through <= 1.4.4.
Published: 2025-03-27
Score: 7.5 High
EPSS: 1.6% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from unsanitized file names used in PHP include/require statements within the WishSuite plugin, allowing a local file to be inadvertently loaded. This flaw can expose sensitive application files or enable execution of arbitrary PHP code, jeopardizing confidentiality, integrity, and availability of the affected website.

Affected Systems

The vulnerability affects the WordPress plugin HT Plugins WishSuite, versions up to and including 1.4.4. All installations of those releases are susceptible until the plugin is updated.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity, while the EPSS score of 2% reflects a moderate probability of immediate exploitation. The flaw is not listed in CISA’s KEV catalog. Attackers are likely to trigger the inclusion through crafted HTTP requests that manipulate file path parameters handled by the plugin. Successful exploitation would grant the attacker access to the local file system or allow them to execute code within the context of the web server if they can compel the plugin to include a malicious script.

Generated by OpenCVE AI on May 7, 2026 at 14:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WishSuite plugin to the latest version that removes the LFI vulnerability.
  • If an update cannot be applied immediately, deactivate or uninstall the WishSuite plugin to eliminate the attack surface.
  • Ensure that the web server’s file permissions restrict read access for web‑accessible directories and that any remaining file‑include operations perform strict path validation to prevent LFI or RFI attempts.

Generated by OpenCVE AI on May 7, 2026 at 14:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8358 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in HT Plugins WishSuite allows PHP Local File Inclusion. This issue affects WishSuite: from n/a through 1.4.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in HT Plugins WishSuite allows PHP Local File Inclusion. This issue affects WishSuite: from n/a through 1.4.4. Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in HT Plugins WishSuite wishsuite allows PHP Local File Inclusion.This issue affects WishSuite: from n/a through <= 1.4.4.
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 27 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 27 Mar 2025 11:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in HT Plugins WishSuite allows PHP Local File Inclusion. This issue affects WishSuite: from n/a through 1.4.4.
Title WordPress WishSuite plugin <= 1.4.4 - Local File Inclusion Vulnerability
Weaknesses CWE-98
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:58.209Z

Reserved: 2025-03-26T09:20:32.697Z

Link: CVE-2025-30820

cve-icon Vulnrichment

Updated: 2025-03-27T13:20:45.742Z

cve-icon NVD

Status : Deferred

Published: 2025-03-27T11:15:43.320

Modified: 2026-04-23T15:27:08.050

Link: CVE-2025-30820

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-07T15:00:13Z

Weaknesses
  • CWE-98

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')