Impact
The vulnerability is a Local File Inclusion flaw in the Flexi – Guest Submit plugin. The plugin fails to properly control the filename used in a PHP include/require statement, allowing attackers to specify arbitrary file paths. If successful, an attacker could read sensitive files on the server and, in some circumstances, execute arbitrary PHP code, compromising the confidentiality, integrity, or availability of the site.
Affected Systems
The flaw affects the odude Flexi – Guest Submit plugin, versions from the first release through 4.28. Any WordPress installation using this plugin and with versions at or below 4.28 is impacted.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. The EPSS score of 2% indicates a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote via a crafted HTTP request that manipulates the plugin’s file inclusion parameter. Exploitation requires only access to the web application, not elevated privileges.
OpenCVE Enrichment
EUVD