high · CVSS v3 7.5 · EPSS 0.00309
CVE-2026-84069
The WebFacing™ WordPress plugin before 5.4 does not restrict access to one of its bundled scripts and does not validate …
Description
The WebFacing™ WordPress plugin before 5.4 does not restrict access to one of its bundled scripts and does not validate a user-supplied path before using it to include a local file, allowing unauthenticated users to perform Local File Inclusion.
Scores
- Severity
- high
- CVSS v2
- 6.4
- CVSS v3
- 7.5
- CVSS v4
- —
- EPSS
- 0.00309