CVE-2025-15491: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-15491 is a Local File Inclusion (LFI) vulnerability in the Post Slides WordPress plugin through version 1.0.1. The flaw allows authenticated users with Contributor-level roles or higher to include arbitrary local files by manipulating shortcode attributes. It was discovered by researcher Khaled Alenazi (Nxploited), added to WPScan on 2026-01-09, and publicly disclosed on 2026-01-16. It carries a CVSS v3.1 base score of 5.5 (Medium) (WPScan, Red Hat CVE).

Technical details

The root cause is improper input validation (CWE-22 – Path Traversal) of shortcode attributes within the Post Slides plugin. Specifically, the plugin passes user-supplied shortcode attribute values directly to PHP include() function calls without sanitizing or restricting the path, enabling path traversal sequences such as ../../../../. An attacker with at least Contributor access can craft a post containing a malicious shortcode like [post-slides skin="../../../../wp-config"] to trigger inclusion of sensitive files such as wp-config.php. No complex preconditions beyond authenticated access are required (WPScan).

Impact

Successful exploitation allows an attacker to read arbitrary files accessible to the web server process, including sensitive configuration files such as wp-config.php, which contains database credentials and secret keys. This can lead to full database compromise, credential theft, and potential escalation to complete site takeover. Confidentiality and integrity are both impacted, though availability is not directly affected (WPScan, Red Hat CVE).

Exploitability

A public proof-of-concept is available via WPScan demonstrating exploitation using a crafted shortcode. The EPSS score is approximately 0.036%, indicating low but non-zero probability of active exploitation. There is no current evidence of in-the-wild exploitation or threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (WPScan).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Post Slides plugin version ≤ 1.0.1 using tools like WPScan or by inspecting plugin directories.
  2. Obtain Contributor access: Register or use an existing account with at least Contributor-level privileges on the target WordPress site.
  3. Create or edit a post: Navigate to the WordPress post editor and insert the malicious shortcode: [post-slides skin="../../../../wp-config"].
  4. Trigger file inclusion: Publish or preview the post. The plugin processes the skin attribute without validation and passes the traversal path to a PHP include() call.
  5. Retrieve sensitive data: The contents of wp-config.php (or another targeted file) are included and potentially rendered in the page response, exposing database credentials, authentication keys, and other sensitive configuration data (WPScan).

Indicators of compromise

  • Logs: WordPress access logs showing POST or GET requests to post pages containing shortcode parameters with path traversal sequences (e.g., ../../../../wp-config).
  • File System: Unexpected access to wp-config.php or other sensitive files outside the plugin's intended directory, visible in server-level file access logs (e.g., Apache/Nginx access logs).
  • Logs: PHP error logs showing include() calls referencing paths outside the plugin's directory, or warnings about failed file inclusions of system files.
  • Process: Unusual database activity following potential credential exposure from wp-config.php inclusion, such as new admin account creation or unauthorized data exports.

Mitigation and workarounds

As of the disclosure date, there is no known fix for the Post Slides plugin through version 1.0.1. Site administrators are advised to immediately deactivate and uninstall the Post Slides plugin until a patched version is released. Additionally, restricting Contributor-level user registration and enforcing the principle of least privilege can reduce exposure. Monitoring file access logs for path traversal patterns is recommended as a detective control (WPScan).

Community reactions

The vulnerability was highlighted in the Wordfence Intelligence Weekly WordPress Vulnerability Report for the week of January 12–18, 2026, indicating it received standard industry tracking attention. No notable vendor statements, significant researcher commentary beyond the original discoverer, or major media coverage have been identified for this vulnerability.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management