
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24635 is a PHP Local File Inclusion (LFI) vulnerability in the DevsBlink EduBlink Core WordPress plugin, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects EduBlink Core versions up to and including 2.0.7. The vulnerability was published on January 23, 2026, with the CVE received from Patchstack and CVSS v3.1 scoring added by CISA-ADP the same day. It carries a CVSS v3.1 base score of 7.5 (High) (NVD, Patchstack).
The root cause is improper neutralization of user-controlled input used in PHP include/require statements (CWE-98), allowing an attacker to manipulate the filename parameter to include arbitrary local files on the server. The attack vector is network-based, requires low privileges (authenticated user), no user interaction, and has high attack complexity, suggesting some precondition or bypass is needed to trigger the inclusion. Exploitation follows the CAPEC-193 pattern (PHP Remote File Inclusion), though in this case the impact is local file inclusion, enabling attackers to read sensitive files or potentially achieve code execution if file upload or log poisoning is possible (NVD, Patchstack).
Successful exploitation can result in high confidentiality, integrity, and availability impact on the affected WordPress installation. An attacker with low-level authenticated access could read sensitive server files (e.g., wp-config.php, /etc/passwd), and if combined with a file upload capability or log poisoning, could escalate to remote code execution. This could lead to full site compromise, credential theft, and potential lateral movement within the hosting environment (NVD).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-24635 as of the available data. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.127%, indicating a low probability of exploitation in the near term. Exploitation requires an authenticated user account, which somewhat limits the attack surface (NVD, Patchstack).
include/require statement — typically exposed via a plugin shortcode, AJAX handler, or page template parameter.../../../../wp-config.php or /etc/passwd) in the vulnerable parameter to include a sensitive local file.../, %2e%2e%2f, ....//) in parameters.wp-config.php or /etc/passwd updated unexpectedly.WordPress site administrators should update the EduBlink Core plugin to a version beyond 2.0.7 that addresses this vulnerability, as reported by Patchstack. If an updated version is not yet available, consider deactivating and removing the plugin until a patch is released. Additionally, restrict plugin access to trusted authenticated roles only, implement a Web Application Firewall (WAF) with LFI detection rules, and ensure PHP's open_basedir restriction is configured to limit file inclusion scope (Patchstack, NVD).
The vulnerability was noted in a Wordfence weekly WordPress vulnerability report covering early January 2026, indicating routine tracking by the WordPress security community. Social media activity was minimal, with a brief mention on Bluesky by TheHackerWire. No significant vendor statements or major researcher commentary beyond standard vulnerability database entries have been identified (Wordfence Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."