Impact
An attacker may exploit a flaw that allows local file inclusion in the WordPress Eleblog – Elementor Blog And Magazine Addons plugin. The vulnerable code improperly validates filenames used in PHP include or require statements, giving access to arbitrary files on the server. This can enable an attacker to read sensitive files, inject malicious code, or ultimately execute arbitrary server‑side code, compromising confidentiality, integrity, and availability.
Affected Systems
WordPress installations that have the Eleblog – Elementor Blog And Magazine Addons plugin installed in any version up to and including 2.0.3. The vulnerability exists from the initial release through version 2.0.3; all current 2.0.3 or older deploys are at risk.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity. The EPSS score is below 1%, indicating low current exploitation probability, and the vulnerability is not in CISA's KEV catalog. Exploitation would likely involve sending a crafted request to a web endpoint that accepts a filename parameter, forcing the server to include a local file. The attack vector is web‑based and may not require authentication, making it potentially reachable to unauthenticated users, but specifics are not detailed in the description.
OpenCVE Enrichment