Back

MEDIUM

WordPress include-file plugin <= 1 - Arbitrary File Download Vulnerability

Published Apr 3, 2025

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in tstafford include-file include-file allows Path Traversal.This issue affects include-file: from n/a through <= 1.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Patchstack
Published Apr 3, 2025
Updated Apr 28, 2026
Reserved Mar 24, 2025
CISA Vulnrichment
Updated Apr 3, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a