
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15491 is a Local File Inclusion (LFI) vulnerability in the Post Slides WordPress plugin through version 1.0.1. The flaw allows authenticated users with Contributor-level roles or higher to include arbitrary local files by manipulating shortcode attributes. It was discovered by researcher Khaled Alenazi (Nxploited), added to WPScan on 2026-01-09, and publicly disclosed on 2026-01-16. It carries a CVSS v3.1 base score of 5.5 (Medium) (WPScan, Red Hat CVE).
The root cause is improper input validation (CWE-22 – Path Traversal) of shortcode attributes within the Post Slides plugin. Specifically, the plugin passes user-supplied shortcode attribute values directly to PHP include() function calls without sanitizing or restricting the path, enabling path traversal sequences such as ../../../../. An attacker with at least Contributor access can craft a post containing a malicious shortcode like [post-slides skin="../../../../wp-config"] to trigger inclusion of sensitive files such as wp-config.php. No complex preconditions beyond authenticated access are required (WPScan).
Successful exploitation allows an attacker to read arbitrary files accessible to the web server process, including sensitive configuration files such as wp-config.php, which contains database credentials and secret keys. This can lead to full database compromise, credential theft, and potential escalation to complete site takeover. Confidentiality and integrity are both impacted, though availability is not directly affected (WPScan, Red Hat CVE).
A public proof-of-concept is available via WPScan demonstrating exploitation using a crafted shortcode. The EPSS score is approximately 0.036%, indicating low but non-zero probability of active exploitation. There is no current evidence of in-the-wild exploitation or threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (WPScan).
[post-slides skin="../../../../wp-config"].skin attribute without validation and passes the traversal path to a PHP include() call.wp-config.php (or another targeted file) are included and potentially rendered in the page response, exposing database credentials, authentication keys, and other sensitive configuration data (WPScan).../../../../wp-config).wp-config.php or other sensitive files outside the plugin's intended directory, visible in server-level file access logs (e.g., Apache/Nginx access logs).include() calls referencing paths outside the plugin's directory, or warnings about failed file inclusions of system files.wp-config.php inclusion, such as new admin account creation or unauthorized data exports.As of the disclosure date, there is no known fix for the Post Slides plugin through version 1.0.1. Site administrators are advised to immediately deactivate and uninstall the Post Slides plugin until a patched version is released. Additionally, restricting Contributor-level user registration and enforcing the principle of least privilege can reduce exposure. Monitoring file access logs for path traversal patterns is recommended as a detective control (WPScan).
The vulnerability was highlighted in the Wordfence Intelligence Weekly WordPress Vulnerability Report for the week of January 12–18, 2026, indicating it received standard industry tracking attention. No notable vendor statements, significant researcher commentary beyond the original discoverer, or major media coverage have been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."