Impact
The BizCalendar Web plugin for WordPress is vulnerable to a local file inclusion flaw triggered through the 'bizcalv' shortcode. Authenticated attackers holding a Contributor role or higher can specify any file path to be included, which allows them to execute PHP code stored on the server. This capability can lead to full code execution, bypass access controls, and theft of sensitive data.
Affected Systems
The vulnerability affects the Setriosoft BizCalendar Web WordPress plugin, all releases version 1.1.0.53 and earlier. Users running any of these versions are susceptible, regardless of the WordPress installation or theme.
Risk and Exploitability
The CVSS base score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests exploitation is unlikely at present. The issue is not listed in the CISA KEV catalog. An attacker would need to be authenticated as a Contributor or higher to launch the attack, typically by submitting a request to the bizcalv shortcode and supplying a crafted file path. Once in place, the attacker can execute arbitrary PHP code on the target server.
OpenCVE Enrichment
EUVD