Impact
Improper handling of file names in an include or require statement allows local file inclusion. This weakness enables an attacker to read or execute arbitrary files on the server, potentially leading to remote code execution or disclosure of sensitive data. The vulnerability is classified as CWE‑98 and carries a CVSS score of 8.1, indicating high severity.
Affected Systems
Users of the Rameez Iqbal Real Estate Manager WordPress plugin version 7.3 or earlier are impacted. The plugin is distributed under WordPress CMS, and the issue is present in every release labeled 7.3 or lower. No other vendors are affected according to CNA data.
Risk and Exploitability
The CVSS score of 8.1 signals high risk, while the EPSS score indicates a very low but existing exploitation probability (<1%). The vulnerability is not listed in the CISA KEV catalog. Attackers could leverage the bug by crafting a URL that points the include statement to a local file; it requires authenticated or unauthenticated access depending on the plugin’s exposure. Given the low exploitation probability and absence from KEV, the immediate threat is moderate, but remediation is recommended to avoid future exploitation potential.
OpenCVE Enrichment
EUVD