Impact
The flaw is a relative path traversal in the WHMPress plugin that permits an attacker to read arbitrary files on the web server by manipulating the file parameter. The vulnerability is categorized as CWE‑35, indicating improper path handling. This local file inclusion can expose sensitive configuration data or credentials that should not be publicly accessible.
Affected Systems
WordPress sites that use the WHMPress plugin versions 6.2 through revision 9 (inclusive) are affected. The plugin is distributed by WHMPress and any installation running these versions of the plugin is vulnerable to the relative path traversal flaw.
Risk and Exploitability
The CVSS score of 7.5 classifies the issue as high severity. The EPSS score of less than 1 % indicates that exploit attempts are currently infrequent, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, because the flaw can be triggered by a crafted HTTP request without authentication, a publicly accessible site could expose confidential files. Administrators should weigh the high impact of unauthorized file disclosure against the low likelihood of exploitation.
OpenCVE Enrichment
EUVD