Impact
The vulnerability arises from improper validation of a filename used in a PHP include/require statement (CWE‑98) within the Fami WooCommerce Compare WordPress plugin. This flaw allows an attacker to read arbitrary local files on the server, which may include sensitive configuration or system files that should remain private.
Affected Systems
Any WordPress installation that employs the Fami WooCommerce Compare plugin in versions n/a through 1.0.5 is affected. The plugin is provided by the vendor zankover and may be found in WordPress plugin repositories under the name "Fami WooCommerce Compare."
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5, indicating high severity. The EPSS score is less than 1%, pointing to a low likelihood of exploitation. It is not listed in the CISA KEV catalog. The flaw permits arbitrary local file inclusion via a web request that supplies a crafted filename, which could expose sensitive configuration or system files on the server.
OpenCVE Enrichment
EUVD