Executive brief
Golo Framework is a WordPress plugin that contains an unauthenticated local file inclusion vulnerability, allowing attackers to read sensitive server files without logging in. This could expose configuration files, database credentials, or other private data stored on the server, potentially leading to account compromise or unauthorized access to the WordPress site.
Technical details
The Golo Framework WordPress plugin versions prior to 1.7.5 are vulnerable to an unauthenticated local file inclusion (LFI) flaw classified as OWASP A3 Injection. The vulnerability allows attackers to craft requests that cause the server to load and expose files it should not, without requiring authentication. Attackers can exploit this over the network to read sensitive server files such as configuration files containing database credentials or other private data. The vulnerability was patched in version 1.7.5, and users should update immediately to mitigate the risk.
Affected products
- Golo Framework < 1.7.5
Timeline
- 2026-08-20: disclosed
- 2026-08-19: patched: Version 1.7.5 released