CVE-2026-84069
Received
Received - Intake
Local File Inclusion in WebFacing WordPress Plugin
Vulnerability report for CVE-2026-84069, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-27
Last updated on: 2026-09-27
Assigner: WPScan
Description
Description
The WebFacing™ WordPress plugin before 5.4 does not restrict access to one of its bundled scripts and does not validate a user-supplied path before using it to include a local file, allowing unauthenticated users to perform Local File Inclusion.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| webfacing | webfacing_wordpress_plugin | to 5.4 (exc) |
| webfacing | webfacing_email_accounts_for_cpanel | From 5.3 (inc) to 5.3.6 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |