WordPress Subscribe to Comments Local File Inclusion and Arbitrary Code Execution Vulnerability

Vulnerability

A local file inclusion vulnerability allowing arbitrary file execution has been identified in the Subscribe to Comments WordPress plugin, affecting versions through 2.1.2. This vulnerability arises from improper handling of the 'Path to header' value, enabling authenticated attackers with administrative privileges to include and execute arbitrary files on the server. Exploitation of this vulnerability could lead to bypassing access controls, accessing sensitive information, or executing PHP code in scenarios where 'safe' file types can be uploaded and included.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive data, execution of malicious code on the server, and privilege escalation on systems where the administrator lacks server control.

Reproduction

To reproduce this vulnerability, navigate to the WordPress admin panel and go to 'Options' under the 'Subscribe to Comments' plugin. In the 'Path to header' field, enter a path to a file you wish to include, such as '/etc/passwd'. After submitting the form, the specified file will be included and its contents can be accessed.

Remediation

Users are advised to upgrade to version 2.3 or later.

Added: Jul 19, 2025, 10:34 AM
Updated: Jul 19, 2025, 10:34 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
10.0
exploitability
6.3
remediation
7.7
relevance
0.3
threat
7.6
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.