Executive brief
The Golo Framework, a WordPress plugin component, contains a security vulnerability that could allow an attacker to access sensitive files on the server. By manipulating file paths, an unauthorized user could potentially view internal system files or execute malicious code. This could lead to the exposure of customer data or a full compromise of the website's operations.
Technical details
A Local File Inclusion (LFI) vulnerability exists in the uxper Golo Framework (golo-framework) plugin for WordPress. The issue stems from improper validation of user-supplied input used in PHP include or require statements (CWE-98). An authenticated attacker with low-level privileges can exploit this over the network to include local files from the server's filesystem. Depending on the server configuration and the presence of other exploitable files, this could lead to sensitive information disclosure or remote code execution. The vulnerability is present in versions up to and including 1.7.3.
Affected products
- uxper Golo Framework (golo-framework) <= 1.7.3
Timeline
- 2026-07-13: disclosed
- 2026-07-13: advisory