
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1988 is a Local File Inclusion (LFI) vulnerability in the Flexi Product Slider and Grid for WooCommerce WordPress plugin (by odude/wpdecent), affecting all versions up to and including 1.0.5. The flaw exists in the flexipsg_carousel shortcode, where the theme parameter is directly concatenated into a file path without sanitization, enabling directory traversal and arbitrary PHP file inclusion. It was published on February 14, 2026, with a CVSS v3.1 base score of 7.5 (High) (Feedly, Red Hat CVE).
The root cause is classified as CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program — 'PHP Remote File Inclusion'), with an underlying path traversal component (CWE-22). The theme parameter passed to the flexipsg_carousel shortcode is concatenated directly into a PHP file path without sanitization or validation, allowing an attacker to inject ../ sequences to traverse directories and include arbitrary PHP files on the server (Feedly, CWE-98). Exploitation requires the attacker to have at least Contributor-level WordPress authentication and the ability to create posts containing shortcodes. Once a malicious file is included, PHP will parse and execute any embedded code within it (CWE-98).
Successful exploitation allows an authenticated attacker (Contributor or above) to include and execute arbitrary PHP files on the web server, resulting in full compromise of confidentiality, integrity, and availability of the affected WordPress installation. An attacker could read sensitive server files, execute system commands, deploy web shells, exfiltrate data, or pivot to other systems accessible from the server (Feedly, Red Hat CVE).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported as of the time of this report. The vulnerability requires Contributor-level authentication, which raises the exploitation bar compared to unauthenticated flaws. The EPSS score is 0.00138 (approximately 0.14%), indicating a low current probability of exploitation in the wild (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been identified.
flexipsg_carousel shortcode with a crafted theme parameter using directory traversal sequences, e.g., [flexipsg_carousel theme="../../../../path/to/malicious"].flexipsg_carousel shortcode with theme parameters containing ../ sequences or unusual path strings; PHP error logs referencing unexpected file inclusion paths.bash, curl, wget, python) following shortcode rendering.Update the Flexi Product Slider and Grid for WooCommerce plugin to a version beyond 1.0.5 that includes proper sanitization and validation of the theme parameter. If an updated version is not yet available, disable or remove the plugin immediately. As a defense-in-depth measure, restrict Contributor-level user registration and post creation capabilities, and deploy a Web Application Firewall (WAF) to detect and block path traversal patterns in shortcode parameters (Feedly, Wordfence).
Wordfence included this vulnerability in their weekly WordPress vulnerability report for February 9–15, 2026, highlighting it as part of a broader set of plugin-level LFI issues (Wordfence). RedPacket Security published an alert and shared it on Mastodon, contributing to community awareness (RedPacket Security). INCIBE (Spain's national cybersecurity agency) also issued an early warning advisory for this vulnerability (INCIBE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."