MEDIUM
WebFacing
CVE published 2026-09-27
CVE-2026-84069
CVE-2026-84069 is a Local File Inclusion vulnerability in the WebFacing WordPress plugin before version 5.4. The plugin does not restrict access to one of its bundled scripts and does not validate a user-supplied path before using it to include a local file, allowing unauthenticated users to perform Local File Inclusion. This vulnerability has a CVSS score of 5.3 and a severity of MEDIUM.