Executive brief
The WP with Spritz plugin for WordPress, which integrates speed-reading technology into websites, contains a security flaw that allows unauthorized individuals to view private files. By sending a specially crafted web request, an attacker can bypass security controls to read sensitive system information, such as configuration files and login credentials. This could lead to a full compromise of the website or the underlying server.
Technical details
A Remote File Inclusion (RFI) vulnerability exists in the WP with Spritz plugin version 1.0 due to improper input validation in the 'wp.spritz.content.filter.php' file. The script uses the PHP 'file_get_contents()' function on a user-supplied 'url' parameter without adequate sanitization. An unauthenticated remote attacker can exploit this by sending a GET request containing local file paths (via directory traversal) or remote URLs. This allows for the disclosure of sensitive local files like '/etc/passwd' or WordPress configuration files, and potentially the execution of remote code if the PHP environment allows remote file wrappers. No patch is currently documented in the advisory.
Affected products
- WordPress WP with Spritz 1.0
Timeline
- 2018-04-25: disclosed: Initial exploit discovery by Wadeek
- 2026-05-17: advisory: CVE published to NVD via VulnCheck