Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Solwin Blog Designer PRO Local File Inclusion Vulnerability

Vulnerability

A local file inclusion vulnerability has been identified in the Solwin Blog Designer PRO plugin for WordPress, affecting versions through 3.4.7. This vulnerability arises from improper control of filenames in include or require statements, allowing for the inclusion of local files from the target website. Such exploitation could potentially lead to the disclosure of sensitive information, like database credentials, and depending on the site's configuration, could allow for a complete takeover of the database.

Impact

Exploitation of this vulnerability could allow an attacker to include local files from the affected website, potentially leading to the disclosure of sensitive information such as database credentials. In some cases, this could result in a complete takeover of the database, depending on the site's configuration.

Remediation

Users are advised to update the Solwin Blog Designer PRO plugin to a version later than 3.4.7. For those unable to update immediately, Patchstack offers a virtual patch that can be applied to mitigate the vulnerability until an official update is available.

Added: Aug 31, 2025, 4:17 AM
Updated: Aug 31, 2025, 4:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
9.1
remediation
0.0
relevance
0.4
threat
8.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.