Impact
An improper control of the filename used in a PHP include/require statement in the FAT Cooming Soon plugin allows a local file inclusion (LFI) attack. If an attacker can influence the included file path, they may read arbitrary files on the server, potentially exposing sensitive data and compromising confidentiality.
Affected Systems
The vulnerability affects the roninwp FAT Cooming Soon WordPress plugin in all releases up to and including version 1.1.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score of 2% indicates a modest probability of exploitation. The issue is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector involves a crafted request that supplies an arbitrary file name to the plugin’s include logic; the attacker must supply a parameter that determines the path of the included file.
OpenCVE Enrichment
EUVD