Impact
The Golo Framework plugin for WordPress versions prior to 1.7.5 is vulnerable to unauthenticated Local File Inclusion. An attacker can request arbitrary local files through the plugin’s input parameters, potentially exposing sensitive data or allowing further compromise. This flaw is identified as CWE‑98 and can lead to unauthorized disclosure of system files.
Affected Systems
The vulnerability affects the Golo Framework WordPress plugin provided by uxper, impacting any WordPress site that has a version older than 1.7.5 installed.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity, but the EPSS score is not available, so the current likelihood of exploitation is uncertain. The vulnerability is not listed in the CISA KEV catalog. Attackers would trigger the flaw by accessing crafted URLs that point to local files; no authentication is required, making it a broad threat to all users of the affected plugin.
OpenCVE Enrichment