Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebCodingPlace Responsive Posts Carousel Pro responsive-posts-carousel-pro allows PHP Local File Inclusion.This issue affects Responsive Posts Carousel Pro: from n/a through <= 15.0.
Published: 2025-08-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper control of filenames in the include/require statement in the PHP code of the WebCodingPlace Responsive Posts Carousel Pro plugin allows local file inclusion; the attacker could retrieve arbitrary files from the server, exposing sensitive configuration or source code. This vulnerability maps to CWE-98 and can lead to information disclosure. The plugin’s code does not sanitize user input that determines the file path, which is the core weakness. The impact is limited to the server where the WordPress site runs but could allow attackers to read files that are not meant to be publicly accessible.

Affected Systems

The WebCodingPlace Responsive Posts Carousel Pro WordPress plugin is affected in all releases up to and including version 15.0. Any site running an earlier version of this plugin is susceptible to the local file inclusion flaw. No specific WordPress core or PHP versions are mentioned as additional constraints.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity, while the EPSS score of less than 1% signals a low exploit probability under current threat data. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is application-level input that can be manipulated by an attacker with at least submit‑level access to the plugin settings, or possibly publicly accessible if the parameter is exposed. The exploit is straightforward, requiring the attacker to specify an arbitrary file name in a request that is processed by the plugin’s include/require logic. Successful exploitation could allow the attacker to read files such as the WordPress configuration, user data, or site source code.

Generated by OpenCVE AI on April 30, 2026 at 09:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest patched version of the Responsive Posts Carousel Pro plugin, which removes the insecure include logic.
  • If an upgrade is not immediately possible, uninstall or disable the plugin to eliminate the vulnerable code path.
  • Examine server logs, file permissions, and configuration files for any signs of exploitation, and remediate any discovered exposed data.

Generated by OpenCVE AI on April 30, 2026 at 09:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-24786 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebCodingPlace Responsive Posts Carousel WordPress Plugin allows PHP Local File Inclusion. This issue affects Responsive Posts Carousel WordPress Plugin: from n/a through 15.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebCodingPlace Responsive Posts Carousel WordPress Plugin allows PHP Local File Inclusion. This issue affects Responsive Posts Carousel WordPress Plugin: from n/a through 15.0. Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebCodingPlace Responsive Posts Carousel Pro responsive-posts-carousel-pro allows PHP Local File Inclusion.This issue affects Responsive Posts Carousel Pro: from n/a through <= 15.0.
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 16 Aug 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Webcodingplace
Webcodingplace responsive Posts Carousel Plugin
Wordpress
Wordpress wordpress
Vendors & Products Webcodingplace
Webcodingplace responsive Posts Carousel Plugin
Wordpress
Wordpress wordpress

Thu, 14 Aug 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 14 Aug 2025 10:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebCodingPlace Responsive Posts Carousel WordPress Plugin allows PHP Local File Inclusion. This issue affects Responsive Posts Carousel WordPress Plugin: from n/a through 15.0.
Title WordPress Responsive Posts Carousel WordPress Plugin Plugin <= 15.0 - Local File Inclusion Vulnerability
Weaknesses CWE-98
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Webcodingplace Responsive Posts Carousel Plugin
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:17.683Z

Reserved: 2025-06-19T10:02:39.647Z

Link: CVE-2025-52728

cve-icon Vulnrichment

Updated: 2025-08-14T18:53:18.135Z

cve-icon NVD

Status : Deferred

Published: 2025-08-14T11:15:42.410

Modified: 2026-04-23T15:32:05.790

Link: CVE-2025-52728

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T09:30:15Z

Weaknesses