Impact
A local file inclusion flaw exists in the Shopify WordPress plugin for versions up through 1.0.0. When a user with contributor privileges accesses the include endpoint, the plugin fails to validate file paths, enabling the caller to read any file that the web server process can access. The vulnerability does not provide code execution; it is limited to disclosure of server files such as configuration data, credentials, or other sensitive information that may be stored on the host.
Affected Systems
All installations of the Shopify plugin for WordPress version 1.0.0 or earlier are affected. Sites that have enabled the plugin and assigned contributor roles to users can exploit the include functionality. The plugin is identified in the vendor data as part of Shopify, and the issue applies to every deployment of the plugin without an upgrade to a newer version.
Risk and Exploitability
The CVSS score of 7.5 indicates a moderate to high severity primarily due to confidentiality impact. The EPSS score of less than 1% suggests a low likelihood of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. An attacker must first possess contributor-level access to trigger the vulnerability, after which any readable file can be exfiltrated. Although code execution is not supported, the possibility of leaking sensitive configuration or credential files elevates the risk. Prompt patching or mitigation is recommended to reduce the potential damage.
OpenCVE Enrichment