Impact
This vulnerability arises from improper handling of filenames in PHP include/require statements within the Ghost Kit plugin. The flaw allows an attacker to supply arbitrary file paths, leading to local file inclusion that could expose sensitive files or, in some contexts, execute malicious code on the affected host.
Affected Systems
The Ghost Kit plugin for WordPress is affected in all releases up to and including version 3.4.1. The vulnerability is present in every installation of Ghost Kit n/a through 3.4.1 regardless of configuration, and requires no special privileges beyond the ability to craft a request to the vulnerable plugin.
Risk and Exploitability
The CVSS score of 8.1 reflects a high impact, and the EPSS score of <1% indicates a low, but not negligible, probability of exploitation. The weakness is not listed in the CISA KEV catalog, and no widespread exploitation is currently documented. An attacker could exploit the flaw via a crafted web request, potentially leading to data disclosure or remote code execution if the included file can be controlled.
OpenCVE Enrichment
EUVD