Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Benjamin Denis SEOPress for MainWP seopress-for-mainwp allows PHP Local File Inclusion.This issue affects SEOPress for MainWP: from n/a through <= 1.4.
Published: 2025-08-20
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from improper control of the filename used in an include/require statement within the SEOPress for MainWP plugin, enabling a local file inclusion flaw. An attacker who can influence the filename can cause the server to read or execute sensitive local files, potentially leading to PHP code execution or data disclosure. The weakness is identified as a File Inclusion vulnerability (CWE-98).

Affected Systems

The affected product is the SEOPress for MainWP plugin, authored by Benjamin Denis. All installations of the plugin from unknown versions up to and including version 1.4 are vulnerable. Any WordPress instance that deploys SEOPress for MainWP version 1.4 or earlier is at risk.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity and the EPSS score of less than 1% suggests a relatively low probability of exploitation observed so far. The vulnerability is not listed in the CISA KEV catalog. An attacker would likely exploit the flaw by triggering the plugin’s include/require path with a crafted filename, possibly via a web request or through the plugin’s administration interface. Proper authentication is required to reach the affected code path, but if the application does not enforce strict permission checks, the local file inclusion could be used to read configuration files or inject malicious code.

Generated by OpenCVE AI on April 30, 2026 at 08:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the SEOPress for MainWP plugin to a version above 1.4, which removes the vulnerable include/require logic.
  • If an immediate update is not possible, configure the web server or PHP to deny the execution of local files and restrict file permissions so that the web user cannot read sensitive files.
  • Monitor the web application for unexpected file inclusion attempts or anomalous PHP execution logs to detect potential exploitation attempts.

Generated by OpenCVE AI on April 30, 2026 at 08:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-25370 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Benjamin Denis SEOPress for MainWP allows PHP Local File Inclusion. This issue affects SEOPress for MainWP: from n/a through 1.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Benjamin Denis SEOPress for MainWP allows PHP Local File Inclusion. This issue affects SEOPress for MainWP: from n/a through 1.4. Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Benjamin Denis SEOPress for MainWP seopress-for-mainwp allows PHP Local File Inclusion.This issue affects SEOPress for MainWP: from n/a through <= 1.4.
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Wed, 20 Aug 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 20 Aug 2025 08:15:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Benjamin Denis SEOPress for MainWP allows PHP Local File Inclusion. This issue affects SEOPress for MainWP: from n/a through 1.4.
Title WordPress SEOPress for MainWP <= 1.4 - Local File Inclusion Vulnerability
Weaknesses CWE-98
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:55.752Z

Reserved: 2025-05-19T14:13:37.940Z

Link: CVE-2025-48298

cve-icon Vulnrichment

Updated: 2025-08-20T17:43:52.373Z

cve-icon NVD

Status : Deferred

Published: 2025-08-20T08:15:33.680

Modified: 2026-04-23T15:31:03.473

Link: CVE-2025-48298

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T08:30:06Z

Weaknesses