Impact
The MyHome Core plugin for WordPress contains an improper control of filename for include/require statements. An attacker can manipulate the filename parameter to include an arbitrary local file. This can expose sensitive content or, if the file contains executable PHP, allow code execution on the web host, potentially leading to full site compromise.
Affected Systems
The vulnerability is present in TangibleWP MyHome Core plugin versions up to and including 4.1.0. Any WordPress installation that has this plugin installed within the affected range is susceptible.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity rating. The EPSS score of less than 1% suggests a relatively low probability of exploitation in the near term, and the vulnerability is not listed in the CISA KEV catalog. Exploitation typically requires an attacker to trigger the plugin’s file inclusion routine with a crafted filename, which is likely achievable via a URL or submitted form within the WordPress site. Given the moderate-to-high severity, administrators should treat this as a serious risk.
OpenCVE Enrichment