Impact
Improper control of filename parameters in the SuitePlugins Login Widget for Ultimate Member plugin permits arbitrary local file inclusion, potentially allowing attackers to read sensitive files or execute malicious code on the affected WordPress site. The plugin's include/require logic does not validate the supplied path, enabling direct inclusion of attacker‑specified files. This flaw can lead to data exposure, privilege escalation, or remote code execution as described in the vulnerability details.
Affected Systems
The vulnerability affects the SuitePlugins Login Widget for Ultimate Member plugin for WordPress versions up to and including 1.1.2. Any WordPress installation using that plugin version is susceptible to local file inclusion attacks.
Risk and Exploitability
The issue is rated with a CVSS score of 7.5, indicating a moderate to high severity. The EPSS score of 1% suggests a low probability of exploitation in the current threat landscape, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector involves manipulating a request to the plugin's login widget to provide a malicious file path. If successful, attackers could read arbitrary files or execute code, leading to full compromise of the affected site. Due to the low EPSS, immediate impact is limited, but the high CVSS warrants timely remediation.
OpenCVE Enrichment
EUVD