Impact
The flaw in codeworkweb Xews Lite allows PHP code to include local files via an improperly validated filename input. This Local File Inclusion flaw can enable an attacker to read arbitrary files or, if the included file can be crafted, execute code on the affected WordPress site. The weakness is identified as CWE‑98 and carries a CVSS score of 7.5, indicating a high impact on confidentiality and integrity for users of the affected plugin.
Affected Systems
The vulnerability impacts installations of the Xews Lite plugin for WordPress, versions 1.0.9 or earlier. The plugin is listed under the vendor codeworkweb.
Risk and Exploitability
The EPSS score of 1% indicates a lower likelihood of exploitation, but the high CVSS indicates that once discovered, an attacker could compromise the site. The flaw is not recorded in CISA’s KEV catalog. It is inferred that the likely attack vector is local file inclusion through the plugin’s input handling, potentially triggered by a crafted request to the WordPress front‑end.
OpenCVE Enrichment
EUVD