Impact
The vulnerability results from improper control of filenames passed to PHP’s include/require statements within the BuddyForms plugin (CWE‑98). User‑supplied file names are used without adequate validation, allowing an attacker to have the plugin include arbitrary local files. Depending on the content of the included file, this can expose sensitive data or enable execution of malicious PHP code, effectively turning the LFI into a remote code execution vector.
Affected Systems
Themekraft BuddyForms plugin used in WordPress installations, all versions up to and including 2.10.2, are affected. The issue applies regardless of other plugins or the WordPress core version.
Risk and Exploitability
CVSS score of 7.5 designates high severity, while an EPSS score of less than 1% indicates exploitation is currently rare but still possible. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a public‑facing form or request that allows the attacker to specify a filename, though the precise input mechanism is not detailed in the description. The flaw is local, requiring some level of access to the WordPress installation, such as interacting with the plugin’s features.
OpenCVE Enrichment
EUVD