Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce User Roles premmerce-user-roles allows PHP Local File Inclusion.This issue affects Premmerce User Roles: from n/a through <= 1.0.13.
Published: 2025-11-06
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Premmerce User Roles plugin suffers from improper control of filenames used in PHP include/require statements. The flaw allows an attacker to specify an arbitrary local file path, leading to a Local File Inclusion vulnerability. If the attacker can access a file containing sensitive data or inject malicious code, the impact ranges from information disclosure to remote code execution. The weakness corresponds to CWE‑98, which is an improper validation of file paths that can be abused to include unintended files.

Affected Systems

The vulnerability affects the Premmerce User Roles WordPress plugin, versions up through 1.0.13. Sites running this plugin on any WordPress installation are potentially impacted unless they are using a later version.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity; however, the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a Local File Inclusion path that can be manipulated via a crafted request to the plugin’s file‑inclusion endpoint. The exploit would require the attacker to have enough privileges or craft the request to the plugin endpoint, but no explicit authentication requirements are stated in the CVE data, so the possibility of unauthenticated exploitation cannot be ruled out.

Generated by OpenCVE AI on April 30, 2026 at 05:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Premmerce User Roles plugin to the latest version, which removes the filename validation flaw.
  • Configure your web application firewall or server to block requests that attempt to include arbitrary file paths when accessing the plugin’s file‑inclusion endpoint, limiting the attack surface.
  • Restrict the plugin’s file‑inclusion functionality to privileged users only; if your setup cannot enforce this, disable that feature until a patch is applied.

Generated by OpenCVE AI on April 30, 2026 at 05:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 06 Nov 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Premmerce
Premmerce user Roles
Wordpress
Wordpress wordpress
Vendors & Products Premmerce
Premmerce user Roles
Wordpress
Wordpress wordpress

Thu, 06 Nov 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce User Roles premmerce-user-roles allows PHP Local File Inclusion.This issue affects Premmerce User Roles: from n/a through <= 1.0.13.
Title WordPress Premmerce User Roles plugin <= 1.0.13 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Premmerce User Roles
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:57.088Z

Reserved: 2025-09-25T15:28:34.981Z

Link: CVE-2025-60193

cve-icon Vulnrichment

Updated: 2025-11-06T20:01:13.212Z

cve-icon NVD

Status : Deferred

Published: 2025-11-06T16:16:04.380

Modified: 2026-04-27T16:16:32.713

Link: CVE-2025-60193

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T05:15:28Z

Weaknesses