Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PluginEver Product Category Slider for WooCommerce woo-category-slider-by-pluginever allows PHP Local File Inclusion.This issue affects Product Category Slider for WooCommerce: from n/a through <= 4.3.4.
Published: 2025-05-19
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in PluginEver’s Product Category Slider for WooCommerce arises from an improper control of filenames used in PHP include/require statements, enabling a local file inclusion flaw. An attacker who can influence the inclusion path could read arbitrary files on the server and, in some configurations, execute code, potentially compromising the confidentiality, integrity, and availability of the hosted WordPress site.

Affected Systems

PluginEver’s Product Category Slider for WooCommerce is vulnerable for all releases up to and including version 4.3.4. The affected software runs within WordPress installations that have installed a vulnerable instance of this plugin.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity while the EPSS score of less than 1 % signals a very low likelihood of current exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, which further suggests the threat level is moderate. Likely bypassing controls would require the attacker to be able to influence the plugin’s file path handling, typically through crafted input or file upload paths, without network exposure. Given the modest exploitation probability, an attacker’s success would largely depend on the presence of other vulnerabilities or misconfigurations that facilitate the inclusion path control. Nonetheless, the potential to read sensitive files or execute code warrants proactive remediation.

Generated by OpenCVE AI on April 30, 2026 at 19:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Product Category Slider for WooCommerce to the latest version released after 4.3.4 thereby eliminating the known local file inclusion flaw.
  • If an immediate update is not possible, deactivate or remove the vulnerable plugin to prevent exploitation until a patch can be applied.
  • Perform a thorough site scan for suspicious files and code, particularly in directories that receive file uploads, and remove any malicious content that may have been introduced via the inclusion vulnerability.

Generated by OpenCVE AI on April 30, 2026 at 19:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-15717 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PluginEver Product Category Slider for WooCommerce allows PHP Local File Inclusion.This issue affects Product Category Slider for WooCommerce: from n/a through 4.3.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PluginEver Product Category Slider for WooCommerce allows PHP Local File Inclusion.This issue affects Product Category Slider for WooCommerce: from n/a through 4.3.4. Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PluginEver Product Category Slider for WooCommerce woo-category-slider-by-pluginever allows PHP Local File Inclusion.This issue affects Product Category Slider for WooCommerce: from n/a through <= 4.3.4.
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Mon, 19 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 19 May 2025 16:30:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PluginEver Product Category Slider for WooCommerce allows PHP Local File Inclusion.This issue affects Product Category Slider for WooCommerce: from n/a through 4.3.4.
Title WordPress Product Category Slider for WooCommerce plugin <= 4.3.4 - Local File Inclusion vulnerability
Weaknesses CWE-98
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:29.545Z

Reserved: 2025-04-16T06:22:20.495Z

Link: CVE-2025-39364

cve-icon Vulnrichment

Updated: 2025-05-19T16:43:54.760Z

cve-icon NVD

Status : Deferred

Published: 2025-05-19T17:15:25.213

Modified: 2026-04-23T15:29:24.890

Link: CVE-2025-39364

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T20:00:14Z

Weaknesses