Impact
Docket Cache plugin for WordPress, version 24.07.03 and earlier, contains an improper control of filename for an include/require statement in PHP. This flaw permits local file inclusion through crafted input, allowing an attacker to read arbitrary files on the server and potentially execute PHP code. The weakness is identified as CWE‑98 and can compromise confidentiality and integrity of the application.
Affected Systems
The vulnerability affects the Nawawi Jamili Docket Cache plugin delivered to WordPress sites. All deployments of the plugin at or below version 24.07.03 are impacted. No specific WordPress core versions are listed.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score being less than 1% signals a low likelihood of exploitation currently. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, where an authenticated or unauthenticated user submits input that resolves to a file path on the server. Successful exploitation could expose sensitive files or facilitate remote code execution if the attacker can trigger PHP execution.
OpenCVE Enrichment