Impact
A vulnerability in the WP Multilang plugin allows an attacker to manipulate the filename used in a PHP include or require statement, resulting in local file inclusion. This flaw can be abused to read sensitive files on the server or to inject and run malicious code, thereby compromising confidentiality and integrity of the system. The weakness is identified as CWE‑98.
Affected Systems
The affected product is the WordPress WP Multilang plugin from Magazine3. All releases up to and including version 2.4.19 are vulnerable. WordPress installations that have this plugin installed in any of those versions are at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, while the EPSS score of less than 1% suggests a low likelihood of real‑world exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack vector would involve an attacker supplying crafted input to the plugin’s file name parameter, enabling the plugin to include arbitrary local files.
OpenCVE Enrichment
EUVD