Impact
Unauthenticated Local File Inclusion in Vavo Core versions 2.3.0 and older allows an attacker to read arbitrary files on the server via the plugin's unsanitized input handling. This could expose sensitive configuration data, user credentials, or other content that must remain confidential. Vulnerability corresponds to CWE-98, an improper restriction of operations with user-supplied input.
Affected Systems
Affected system is the Vavo Core WordPress plugin from SpabRice, versions up to and including 2.3.0. WordPress sites running these versions are at risk and may have the plugin installed in active use.
Risk and Exploitability
The CVSS base score of 8.1 indicates a high severity. EPSS is not available, and the vulnerability is not listed in CISA KEV. An attacker can exploit the LFI by sending specially constructed requests to the plugin endpoint, without requiring valid authentication. The lack of access control makes the attack vector public, meaning any entity able to interact with the WordPress site could attempt exploitation.
OpenCVE Enrichment