Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in villatheme Sales Countdown Timer for WooCommerce and WordPress sctv-sales-countdown-timer allows PHP Local File Inclusion.This issue affects Sales Countdown Timer for WooCommerce and WordPress: from n/a through < 1.1.9.
Published: 2026-02-19
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Local file inclusion that may lead to code execution
Action: Immediate Patch
AI Analysis

Impact

An attacker can supply a target filename used by the Sales Countdown Timer plugin’s PHP include/require logic, enabling local file inclusion. Because the plugin does not validate or sanitize the path, an attacker can read sensitive configuration, log, or webroot files and, if the server allows execution of included PHP, run arbitrary code, compromising confidentiality, integrity, and availability of the WordPress site.

Affected Systems

The flaw affects any installation of the Sales Countdown Timer for WooCommerce and WordPress plugin from Villatheme that is version 1.1.8 or earlier. The plugin is a WordPress extension used with WooCommerce to display countdown timers.

Risk and Exploitability

The flaw carries a base severity score of 7.5, labeling it high severity. Exploit probability is calculated to be very low (<1%), indicating that current exploitation attempts are rare, and the vulnerability is not listed in the catalog of known exploited vulnerabilities. Attackers can exploit it through a web request that points the plugin’s file inclusion mechanism to an arbitrary local file. No privileged credentials are required, so any publicly accessible site that runs a vulnerable plugin version is at risk; potential impact ranges from reading files to executing code if the server’s configuration permits local file inclusion.

Generated by OpenCVE AI on April 16, 2026 at 06:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Sales Countdown Timer for WooCommerce and WordPress plugin to version 1.1.9 or later, which removes the vulnerable file‑inclusion logic.
  • If an upgrade is not yet possible, disable or delete the plugin from the WordPress installation to eliminate the attack surface.
  • Apply server‑side mitigations such as setting allow_url_include off, restricting file permissions for wp‑content uploads, and validating any file paths used by plugins before inclusion.

Generated by OpenCVE AI on April 16, 2026 at 06:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in VillaTheme Sales Countdown Timer for WooCommerce and WordPress allows PHP Local File Inclusion.This issue affects Sales Countdown Timer for WooCommerce and WordPress: from n/a before 1.1.9. Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in villatheme Sales Countdown Timer for WooCommerce and WordPress sctv-sales-countdown-timer allows PHP Local File Inclusion.This issue affects Sales Countdown Timer for WooCommerce and WordPress: from n/a through < 1.1.9.
References

Tue, 17 Mar 2026 09:30:00 +0000


Tue, 17 Mar 2026 08:30:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in villatheme Sales Countdown Timer for WooCommerce and WordPress sctv-sales-countdown-timer allows PHP Local File Inclusion.This issue affects Sales Countdown Timer for WooCommerce and WordPress: from n/a through <= 1.1.8.1. Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in VillaTheme Sales Countdown Timer for WooCommerce and WordPress allows PHP Local File Inclusion.This issue affects Sales Countdown Timer for WooCommerce and WordPress: from n/a before 1.1.9.
Title WordPress Sales Countdown Timer for WooCommerce and WordPress plugin <= 1.1.8.1 - Local File Inclusion vulnerability WordPress Sales Countdown Timer for WooCommerce and WordPress plugin < 1.1.9 - Local File Inclusion vulnerability
References

Fri, 20 Feb 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Villatheme
Villatheme sales Countdown Timer For Woocommerce And Wordpress
Wordpress
Wordpress wordpress
Vendors & Products Villatheme
Villatheme sales Countdown Timer For Woocommerce And Wordpress
Wordpress
Wordpress wordpress

Fri, 20 Feb 2026 01:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 19 Feb 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 19 Feb 2026 08:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in villatheme Sales Countdown Timer for WooCommerce and WordPress sctv-sales-countdown-timer allows PHP Local File Inclusion.This issue affects Sales Countdown Timer for WooCommerce and WordPress: from n/a through <= 1.1.8.1.
Title WordPress Sales Countdown Timer for WooCommerce and WordPress plugin <= 1.1.8.1 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Villatheme Sales Countdown Timer For Woocommerce And Wordpress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:15:00.961Z

Reserved: 2026-02-17T13:23:30.505Z

Link: CVE-2026-27052

cve-icon Vulnrichment

Updated: 2026-02-19T18:04:43.088Z

cve-icon NVD

Status : Deferred

Published: 2026-02-19T09:16:26.527

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-27052

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T06:30:06Z

Weaknesses