Threats Tagged 'cwe-98'
View all threats tagged with 'cwe-98'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-98'
Click on any threat for detailed analysis and mitigation recommendations
The Visual Composer Website Builder plugin for WordPress contains a critical Local File Inclusion vulnerability in all versions up to and including 45.16.0. This flaw allows unauthenticated attackers to include and execute arbitrary files on the server via the 'vcv-template' parameter. Successful exploitation can lead to execution of arbitrary PHP code, bypassing access controls and potentially exposing sensitive data or enabling full code execution. Join the discussion | CVE Database V5 | 09/24/2026, 09:27:45 UTC Added: 09/24/2026, 09:48:25 UTC |
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.8.0 via the wte_get_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. Join the discussion | CVE Database V5 | 09/22/2026, 08:27:18 UTC Added: 09/23/2026, 01:58:22 UTC |
The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.4 via the 'shortcode' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. This vulnerability is exploitable by unauthenticated users because the only access control is a nonce check against woof_front_nonce, which is publicly emitted into inline JavaScript on every front-end page and is therefore obtainable by any site visitor without authentication. Join the discussion | CVE Database V5 | 09/22/2026, 07:41:10 UTC Added: 09/22/2026, 08:03:18 UTC |
The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is included at render time, allowing users with contributor-level access and above to include arbitrary local files, disclose their contents, and execute PHP where a local file containing PHP code can be reached. Exploitation requires the plugin's Lightspeed subsystem to be enabled, which is not the default. Join the discussion | CVE Database V5 | 09/18/2026, 06:11:38 UTC Added: 09/18/2026, 06:47:16 UTC |
A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP code on the device. Join the discussion | CVE Database V5 | 09/16/2026, 07:50:20 UTC Added: 09/16/2026, 08:02:22 UTC |
A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP code on the device. Join the discussion | CVE Database V5 | 09/16/2026, 07:50:08 UTC Added: 09/16/2026, 08:02:20 UTC |
The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. In environments where PEAR is installed with register_argc_argv enabled, this file inclusion can be leveraged to write and execute arbitrary PHP code, achieving full remote code execution. Join the discussion | CVE Database V5 | 09/12/2026, 07:39:14 UTC Added: 09/12/2026, 07:47:01 UTC |
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The etn_manage_event capability is assigned to Contributors by default, meaning any Contributor-level user can set the malicious event_layout value via the REST API without any additional configuration. Join the discussion | CVE Database V5 | 09/09/2026, 02:27:35 UTC Added: 09/09/2026, 02:37:55 UTC |
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with custom-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. Join the discussion | CVE Database V5 | 09/09/2026, 02:27:35 UTC Added: 09/09/2026, 02:37:55 UTC |
The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. This vulnerability is only exploitable when the loop_templates parameter is set to 'custom-template'. Join the discussion | CVE Database V5 | 09/04/2026, 04:29:08 UTC Added: 09/04/2026, 04:37:45 UTC |
Showing 1 to 10 of 276 results