Impact
The Shopify WordPress plugin contains a local file inclusion flaw that is triggered when a contributor user requests a file to be included. An attacker who has contributor‑level access can submit arbitrary file paths, causing the plugin to read and expose any file the web process can access. This results in a confidentiality breach; the flaw does not grant code execution or modification rights, but it can leak configuration files, credentials and other sensitive data.
Affected Systems
All releases of the Shopify WordPress plugin up to and including version 1.0.0 that are installed on WordPress sites. The vulnerability applies whenever a user with contributor permissions accesses the plugin’s include functionality. Sites that have granted contributor roles and have the plugin active are affected.
Risk and Exploitability
The CVSS score of 7.5 indicates a moderate‑to‑high severity primarily because of the impact on confidentiality. The EPSS score of < 1% shows a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog. Based on the plugin’s include endpoint; the attacker can then trigger a local file inclusion, read arbitrary files, and potentially expose sensitive information. Overall risk is moderate, but the confidentiality impact warrants prompt remediation.
OpenCVE Enrichment