Impact
A local file inclusion flaw exists in the immonex Kickstart Team WordPress plugin that allows an attacker to supply an arbitrary filename to a PHP include/require statement. The vulnerability is classified as CWE‑98 and can enable the reading of unintended files on the server, potentially exposing configuration data or sensitive user information. The description explicitly notes that the flaw permits PHP local file inclusion and does not state that remote code execution is assured.
Affected Systems
All installations of the immonex Kickstart Team plugin that are version 1.6.9 or earlier are affected. The vulnerability applies to the plugin across its entire supported version range from the earliest release through 1.6.9; any deployment of these or older versions should be considered exposed.
Risk and Exploitability
The flaw carries a CVSS score of 7.5, classifying it as high severity. The EPSS score of less than 1 % indicates that, as of the current analysis, the likelihood of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is likely through a web request that controls the filename parameter used by the plugin; any authenticated or unauthenticated user who can submit requests may achieve file reading, and if the included file contains executable code, the impact could be escalated further.
OpenCVE Enrichment
EUVD