Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Processby Lazy Load Optimizer lazy-load-optimizer allows PHP Local File Inclusion.This issue affects Lazy Load Optimizer: from n/a through <= 1.4.7.
Published: 2025-11-06
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper control of a filename used in PHP’s include or require statements, allowing an attacker to trigger local file inclusion. This can lead to arbitrary reading of local files and potentially further compromise if the read data is used in subsequent operations. The weakness is classified as CWE‑98 and presents a risk of data exposure and further exploitation depending on the context of the included files.

Affected Systems

WordPress sites using the Lazy Load Optimizer plugin version 1.4.7 or earlier are affected. The plugin, developed by Processby, is common in sites that enable lazy loading of images and other media. No specific operating system or WordPress core version is singled out in the advisory, so any installation of the plugin in the listed version range could be vulnerable.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity, while an EPSS score of less than 1% suggests low current exploitation probability. The vulnerability is not included in the CISA Known Exploited Vulnerabilities catalog, indicating no confirmed public exploits. Given the nature of LFI, the attack vector is likely local or via authenticated access to the plugin’s settings page, and an attacker may need a valid user session or an administrative account to supply a crafted file path. Once triggered, the attacker could read sensitive files such as configuration files or potentially execute code if the included file contains malicious content.

Generated by OpenCVE AI on April 29, 2026 at 23:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Lazy Load Optimizer to a version newer than 1.4.7 or apply the vendor’s patch if available.
  • If upgrading is not immediately possible, disable the Lazy Load Optimizer plugin to remove the vulnerable include path.
  • Configure the web server or WordPress environment to restrict include paths and set strict file permissions so that only intended plugin files can be read via include/require statements.

Generated by OpenCVE AI on April 29, 2026 at 23:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 06 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Nov 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 06 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Processby Lazy Load Optimizer lazy-load-optimizer allows PHP Local File Inclusion.This issue affects Lazy Load Optimizer: from n/a through <= 1.4.7.
Title WordPress Lazy Load Optimizer plugin <= 1.4.7 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:54.143Z

Reserved: 2025-09-25T15:19:48.981Z

Link: CVE-2025-60074

cve-icon Vulnrichment

Updated: 2025-11-06T21:30:17.819Z

cve-icon NVD

Status : Deferred

Published: 2025-11-06T16:16:03.250

Modified: 2026-04-27T18:16:23.853

Link: CVE-2025-60074

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T23:30:22Z

Weaknesses