Impact
The Biagiotti Core plugin (versions up to 2.1.1) is vulnerable to an unauthenticated local file inclusion flaw (CWE‑98). The flaw allows any user to craft a request that causes the plugin to include arbitrary files from the server’s file system in the HTTP response, potentially revealing sensitive configuration files, environment variables, or other data that should remain private. Because the inclusion is performed without validating the requested path, an attacker could include executable files, leading to remote code execution or further compromise of the application.
Affected Systems
The affected product is the Biagiotti Core plugin developed by Mikado‑Themes. All releases through version 2.1.1 are impacted; newer releases are not listed and are therefore presumed secure.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity flaw, and although the EPSS score is not provided, the lack of authentication requirement makes the attack vector readily exploitable from any client that can reach the site. The vulnerability is not currently listed in the CISA KEV catalog, but its impact on confidentiality, integrity, and availability warrants immediate attention. An attacker could exploit the flaw by sending crafted requests to the plugin’s endpoints, triggering inclusion of arbitrary files and potentially executing code or exfiltrating sensitive data.
OpenCVE Enrichment