Impact
The NooTheme Jobmonster Elementor Addon plugin contains an improper control of filename for include/require, allowing a local file inclusion (LFI) vulnerability. An attacker who can influence the filename parameter can force the plugin to include arbitrary local files, which may lead to disclosure of sensitive data or execution of arbitrary PHP code. The weakness is identified as CWE‑98.
Affected Systems
Affected are WordPress sites that have the NooTheme Jobmonster Elementor Addon plugin installed at version 1.1.4 or earlier. The vulnerability is present in all releases from the first plugin launch through version 1.1.4.
Risk and Exploitability
The CVSS score of 7.5 rates the vulnerability as high severity. The EPSS < 1% score indicates that, at present, the expected exploitation rate is very low, and it is not listed in the CISA KEV catalog. However, if an attacker can inject a path traversal string or otherwise influence the include path, local files such as configuration files, logs, or even PHP files could be read or executed, leading to possible remote code execution. The attack vector is most likely through a specially crafted HTTP request that includes the vulnerable parameter.
OpenCVE Enrichment