Impact
The vulnerability is a local file inclusion flaw in the MagicAI for WordPress plugin up to version 1.4. It permits subscriber-level users to supply a file path that the plugin will include and display. The flaw can be used to read any file accessible to the web server’s process, exposing configuration files, credentials, or other sensitive data. The impact is primarily data exposure and may serve as a foothold for more advanced attacks if the attacker can identify exploitable scripts or misconfigurations within the server.
Affected Systems
The affected system is the LiquidThemes MagicAI for WordPress – AI Text, Image, Chat, Code, and Voice Generator plugin, version 1.4 and earlier. No other vendors or versions are listed.
Risk and Exploitability
The CVSS score of 8.8 denotes high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests that public exploitation data is currently limited. The attack vector is inferred to be via a subscriber’s ability to trigger the file inclusion, requiring authenticated access to the plugin. Once the file path is supplied, the plugin reads and presents the file contents, potentially leaking sensitive information.
OpenCVE Enrichment