Description
Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions.
Published: 2026-08-20
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Golo Framework plugin for WordPress versions prior to 1.7.5 is vulnerable to unauthenticated Local File Inclusion. An attacker can request arbitrary local files through the plugin’s input parameters, potentially exposing sensitive data or allowing further compromise. This flaw is identified as CWE‑98 and can lead to unauthorized disclosure of system files.

Affected Systems

The vulnerability affects the Golo Framework WordPress plugin provided by uxper, impacting any WordPress site that has a version older than 1.7.5 installed.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity, but the EPSS score is not available, so the current likelihood of exploitation is uncertain. The vulnerability is not listed in the CISA KEV catalog. Attackers would trigger the flaw by accessing crafted URLs that point to local files; no authentication is required, making it a broad threat to all users of the affected plugin.

Generated by OpenCVE AI on August 20, 2026 at 21:19 UTC.

Remediation

Vendor Solution

Update the WordPress Golo Framework Plugin to the latest available version (at least 1.7.5).


OpenCVE Recommended Actions

  • Upgrade the Golo Framework Plugin to version 1.7.5 or later.
  • If an upgrade is not feasible, remove the plugin from the WordPress installation.
  • Configure the web server or application firewall to block file path traversal and restrict file inclusion paths used by the plugin.

Generated by OpenCVE AI on August 20, 2026 at 21:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Uxper
Uxper golo Framework
Wordpress
Wordpress wordpress
Vendors & Products Uxper
Uxper golo Framework
Wordpress
Wordpress wordpress

Thu, 20 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Description Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions.
Title WordPress Golo Framework plugin < 1.7.5 - Local File Inclusion vulnerability
Weaknesses CWE-98
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Uxper Golo Framework
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-20T16:27:29.655Z

Reserved: 2026-02-25T12:14:24.000Z

Link: CVE-2026-28150

cve-icon Vulnrichment

Updated: 2026-08-20T16:20:25.791Z

cve-icon NVD

Status : Deferred

Published: 2026-08-20T12:16:32.283

Modified: 2026-08-20T17:17:28.380

Link: CVE-2026-28150

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T21:30:05Z

Weaknesses
  • CWE-98

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')