Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nitin Prakash WC Place Order Without Payment allows PHP Local File Inclusion. This issue affects WC Place Order Without Payment: from n/a through 2.6.7.
CVE ID: CVE-2025-26933
CVSS Base Severity: HIGH
CVSS Base Score: 7.5
CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Vendor: Nitin Prakash
Product: WC Place Order Without Payment
EPSS Score: 0.11% (probability of being exploited)
EPSS Percentile: 26.75% (scored less or equal to compared to others)
EPSS Date: 2025-04-08 (when was this score calculated)