Impact
The vulnerability arises from unsanitized file names used in PHP include/require statements within the WishSuite plugin, allowing a local file to be inadvertently loaded. This flaw can expose sensitive application files or enable execution of arbitrary PHP code, jeopardizing confidentiality, integrity, and availability of the affected website.
Affected Systems
The vulnerability affects the WordPress plugin HT Plugins WishSuite, versions up to and including 1.4.4. All installations of those releases are susceptible until the plugin is updated.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, while the EPSS score of 2% reflects a moderate probability of immediate exploitation. The flaw is not listed in CISA’s KEV catalog. Attackers are likely to trigger the inclusion through crafted HTTP requests that manipulate file path parameters handled by the plugin. Successful exploitation would grant the attacker access to the local file system or allow them to execute code within the context of the web server if they can compel the plugin to include a malicious script.
OpenCVE Enrichment
EUVD