Impact
Based on the description, the RadiusBlocks WordPress plugin is vulnerable to an improper control of filename for include/require statements, identified as CWE-98. The flaw permits an attacker to supply a path that is passed to PHP’s include or require functions, allowing the server to read or execute arbitrary local files. If an attacker were to include a file containing malicious PHP code, this could lead to remote code execution or disclosure of sensitive configuration data. The CVE indicates that all releases up to and including version 2.2.1 are affected; no fixed release is mentioned in the CVE data.
Affected Systems
The RadiusBlocks WordPress plugin from RadiusTheme is the affected product. All installed versions through 2.2.1 are vulnerable. Versions beyond 2.2.1 are not listed as fixed in the CVE data.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of 2% suggests a low but non‑negligible exploitation probability. The likely attack vector is a crafted HTTP request to a plugin endpoint that accepts a file path, enabling inclusion of arbitrary local files if not properly validated. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
EUVD