Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Alexander AnyComment anycomment allows PHP Local File Inclusion.This issue affects AnyComment: from n/a through <= 0.3.6.
Published: 2025-11-06
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The AnyComment plugin for WordPress contains an improper control of filename for include/require. By supplying attacker‑controlled path values, an attacker could trigger PHP's include function with arbitrary local file names, potentially exposing sensitive local files or allowing the execution of malicious code. This flaw is classified as CWE‑98 and can compromise confidentiality and integrity of the server hosting the site.

Affected Systems

This vulnerability affects the Alexander AnyComment plugin version 0.3.6 and earlier on WordPress installations. Systems running any of these versions are impacted. No additional product or version information is provided.

Risk and Exploitability

With a CVSS score of 7.5 the vulnerability is considered high impact, yet the EPSS score of less than 1% indicates a very low probability of exploitation at present and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local file inclusion, typically triggered through plugin parameters or crafted URLs that influence the include path. Successful exploitation would require the attacker to have the ability to influence the plugin’s input and to have access to the site’s file system; it does not grant remote code execution on its own but can lead to disclosure of local files or remote code execution if the attacker can place a malicious script on the server.

Generated by OpenCVE AI on April 29, 2026 at 13:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the AnyComment plugin to version 0.3.7 or later to remove the vulnerable include logic.
  • If an update is not immediately possible, disable the AnyComment plugin or the specific functionality that performs file inclusion to prevent abuse.
  • Restrict file inclusion to trusted directories by adjusting the plugin’s configuration or employing web application firewall rules to block suspicious path inputs.

Generated by OpenCVE AI on April 29, 2026 at 13:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Fri, 07 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 06 Nov 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 06 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Alexander AnyComment anycomment allows PHP Local File Inclusion.This issue affects AnyComment: from n/a through <= 0.3.6.
Title WordPress AnyComment plugin <= 0.3.6 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T18:43:50.930Z

Reserved: 2025-09-25T15:34:44.964Z

Link: CVE-2025-60240

cve-icon Vulnrichment

Updated: 2025-11-07T14:19:31.338Z

cve-icon NVD

Status : Deferred

Published: 2025-11-06T16:16:06.613

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-60240

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T14:00:12Z

Weaknesses