Impact
WordPress WP Subscription Forms plugin up to version 1.2.4 suffers from a filename control flaw in a PHP include/require statement, allowing an attacker to direct the application to include arbitrary local files. This vulnerability can be exploited to read sensitive server files or potentially execute arbitrary code if the included file can be crafted accordingly, compromising confidentiality, integrity, and operational availability. The weakness is classified as CWE-98.
Affected Systems
The flaw affects the WP Shuffle WP Subscription Forms plugin versions from the earliest available releases up to and including 1.2.4. Any WordPress site that has this plugin installed and has not been upgraded beyond 1.2.4 is susceptible.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity for this local file inclusion flaw. The EPSS score of 2% suggests that exploitation likelihood is low at present, and the vulnerability is not listed in the CISA KEV catalog, further indicating limited observed exploitation. Nevertheless, the attack surface of a local file inclusion can be significant in shared hosting or misconfigured environments. Risk remains high enough that remediation should not be delayed.
OpenCVE Enrichment
EUVD