Impact
Improper validation of filenames used in PHP include/require statements in the Premium Addons for KingComposer plugin allows an attacker to include arbitrary local files. By controlling the filename input, the attacker can expose sensitive configuration files, credentials, or, if a crafted file is present or can be placed on the server, pivot towards remote code execution. The flaw is classified as a Local File Inclusion vulnerability, a type of PHP Remote File Inclusion weakness.
Affected Systems
All installations of Octagon Web Studio’s Premium Addons for KingComposer plugin on WordPress sites running version 1.1.1 or earlier are vulnerable. Any release newer than 1.1.1 is presumed to contain the fix. WordPress sites activated with the vulnerable plugin without applying the update remain at risk.
Risk and Exploitability
The CVSS score of 8.1 places this issue in the high severity range. The EPSS score is under 1%, indicating a low short‑term exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector likely involves crafting an HTTP request that supplies or manipulates the filename parameter exposed by the plugin. Although the vulnerability is local, an attacker can read files that the web server can access, which may facilitate subsequent exploits. Organizations should treat this as a critical stance due to the potential impact despite the currently low exploitation likelihood.
OpenCVE Enrichment
EUVD