WordPress Plugin Vulnerabilities

WebFacing Email Accounts for cPanel 5.3 - 5.3.6 - Unauthenticated LFI via assets/index.php

Description

The plugin does not restrict access to one of its bundled scripts and does not validate a user-supplied path before using it to include a local file, allowing unauthenticated users to perform Local File Inclusion.

Proof of Concept

Affects Plugins

References

Classification

Type
LFI
OWASP top 10
CWE

Miscellaneous

Original Researcher
nobody
Submitter
Aleksandar
Verified
Yes

Timeline

Publicly Published
2026-09-24 (about 2 days ago)
Added
2026-09-17 (about 9 days ago)
Last Updated
2026-09-22 (about 4 days ago)

Other