Sceawere
Vulnerability Detail
CVE-2026-84069UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WebFacing WordPress Local File Inclusion
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 1d ago
- Vendor
- Unknown
- Product
- WebFacing™
- Attack Type
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The WebFacing™ WordPress plugin before 5.4 does not restrict access to one of its bundled scripts and does not validate a user-supplied path before using it to include a local file, allowing unauthenticated users to perform Local File Inclusion.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-09-27T06:17:06.560Z",
"pubdate": "2026-09-27T06:17:06.560Z",
"executiveSummary": "The WebFacing WordPress plugin, in versions prior to 5.4, is susceptible to an unauthenticated Local File Inclusion (LFI) vulnerability. This security flaw stems from the improper handling of user-supplied input within a bundled script, which fails to implement necessary access control or input validation mechanisms.\nThe vulnerability allows an unauthenticated remote attacker to include arbitrary local files residing on the host server. By manipulating the request parameters, an attacker can traverse the file system and access sensitive configuration files, system credentials, or source code. The impact is critical, as successful exploitation may lead to full site compromise, remote code execution (if coupled with log poisoning or file upload vectors), and complete disclosure of sensitive information contained within the WordPress environment.\nThis vulnerability is particularly severe due to the lack of required authentication or high-level privileges, meaning any visitor can exploit the flaw. Organizations utilizing versions of WebFacing prior to 5.4 are at significant risk of unauthorized data access and potential server-side compromise. Immediate remediation through upgrading to the patched version is essential to maintain the security posture of the WordPress installation.",
"technicalDetails": "The vulnerability resides in a bundled script within the WebFacing WordPress plugin that fails to perform adequate input validation on user-supplied path parameters. The root cause is a Lack of Input Validation and missing access control checks, which allows the application to process malicious input as a valid file path for inclusion functions, such as include() or require().\nIn the affected versions (prior to 5.4), the plugin does not enforce a whitelist or sanitize the input to prevent directory traversal sequences (e.g., ../). Consequently, an attacker can supply crafted URIs containing path traversal strings to break out of the intended directory context. This facilitates the inclusion of sensitive local files, such as 'wp-config.php', which often contains database credentials, salts, and secret keys, or underlying system files like '/etc/passwd' depending on the server's permission structure.\nThe attack flow proceeds as follows: First, the attacker identifies the publicly accessible bundled script within the plugin structure. Second, the attacker sends an HTTP request to this script, injecting a path traversal payload into the vulnerable parameter. Third, the application receives the input and, due to the lack of validation, directly uses it in a file inclusion operation. Finally, the server processes the request, opens the targeted local file, and reflects the content of that file back in the HTTP response or executes its contents if the file is a PHP script.\nBecause the vulnerability exists in a script that does not mandate session-based authentication or specific user privileges, the exploit is available to any unauthenticated actor with network access to the web server. There are no complex prerequisites or pre-existing conditions required for successful exploitation other than reaching the vulnerable script via a standard web request.\nPost-exploitation impact ranges from information disclosure to full-scale server compromise. By reading sensitive configuration files, an attacker can gain the information necessary to connect to the site's database, alter plugin configurations, or perform further attacks. Furthermore, if the attacker can influence the content of an included file through other vectors—such as log file poisoning, where PHP code is injected into web server access logs—the LFI vulnerability can be leveraged to achieve arbitrary remote code execution (RCE) with the privileges of the web server user."
}