rootpwn

high · CVSS v3 7.5 · EPSS 0.00309

CVE-2026-84069

The WebFacing™ WordPress plugin before 5.4 does not restrict access to one of its bundled scripts and does not validate …

Description

The WebFacing™ WordPress plugin before 5.4 does not restrict access to one of its bundled scripts and does not validate a user-supplied path before using it to include a local file, allowing unauthenticated users to perform Local File Inclusion.

Scores

Severity
high
CVSS v2
6.4
CVSS v3
7.5
CVSS v4
—
EPSS
0.00309

← All CVEs