Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TangibleWP MyHome Core myhome-core allows PHP Local File Inclusion.This issue affects MyHome Core: from n/a through <= 4.1.0.
Published: 2026-01-22
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Local File Inclusion
Action: Apply Patch
AI Analysis

Impact

The MyHome Core plugin for WordPress contains an improper control of filename for include/require statements. An attacker can manipulate the filename parameter to include an arbitrary local file. This can expose sensitive content or, if the file contains executable PHP, allow code execution on the web host, potentially leading to full site compromise.

Affected Systems

The vulnerability is present in TangibleWP MyHome Core plugin versions up to and including 4.1.0. Any WordPress installation that has this plugin installed within the affected range is susceptible.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity rating. The EPSS score of less than 1% suggests a relatively low probability of exploitation in the near term, and the vulnerability is not listed in the CISA KEV catalog. Exploitation typically requires an attacker to trigger the plugin’s file inclusion routine with a crafted filename, which is likely achievable via a URL or submitted form within the WordPress site. Given the moderate-to-high severity, administrators should treat this as a serious risk.

Generated by OpenCVE AI on April 27, 2026 at 21:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MyHome Core to the latest version that removes the vulnerable include logic.
  • If an update is not available, disable or uninstall the plugin to eliminate the input path that can be abused.
  • Configure the web server to deny execution of arbitrary local files and restrict file permissions on the WordPress installation folders.
  • Implement a web application firewall to block requests containing malicious file paths and monitor logs for suspicious inclusion attempts.

Generated by OpenCVE AI on April 27, 2026 at 21:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 29 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TangibleWP MyHome Core myhome-core allows PHP Local File Inclusion.This issue affects MyHome Core: from n/a through <= 4.1.0.
Title WordPress MyHome Core plugin <= 4.1.0 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:24.631Z

Reserved: 2025-12-15T10:00:16.553Z

Link: CVE-2025-67955

cve-icon Vulnrichment

Updated: 2026-01-29T18:36:16.921Z

cve-icon NVD

Status : Deferred

Published: 2026-01-22T17:16:05.033

Modified: 2026-04-27T18:16:51.360

Link: CVE-2025-67955

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-27T21:45:14Z

Weaknesses