
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32537 is a Local File Inclusion (LFI) vulnerability in the Visual Portfolio, Photo Gallery & Post Grid WordPress plugin developed by nK. It affects all versions up to and including 3.5.1, and was patched in version 3.5.2. The vulnerability was reported by researcher Nguyen Ba Khanh on February 1, 2026, and published by Patchstack on March 20, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Patchstack).
The vulnerability is classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program — 'PHP Remote File Inclusion'), but the actual exploitation path is Local File Inclusion (LFI). The flaw arises from insufficient validation of user-supplied input used in PHP include/require statements within the plugin, allowing an attacker to manipulate file path parameters to include arbitrary local files from the server. Exploitation requires low privileges (Subscriber-level authentication) and high attack complexity, but no user interaction (Patchstack).
Successful exploitation allows an attacker to read arbitrary local files on the web server, including sensitive configuration files such as wp-config.php, which contains database credentials. This could lead to complete database takeover, exposure of authentication secrets, and potential for further lateral movement within the hosting environment. Confidentiality, integrity, and availability are all rated as High impact (Patchstack).
The vulnerability has a low EPSS score of approximately 0.114%, suggesting limited observed exploitation activity at this time. No public proof-of-concept exploit code or active in-the-wild exploitation campaigns have been confirmed, and it does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies it as High priority, noting that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress sites at scale. The vulnerability requires Subscriber-level authentication, which is a low barrier on sites with open registration (Patchstack).
inurl:wp-content/plugins/visual-portfolio).include/require call — typically exposed via a REST API endpoint, shortcode handler, or AJAX action.../../../../wp-config.php or /etc/passwd) as the parameter value in a crafted HTTP request to the vulnerable endpoint.../, ..%2F, or absolute paths like /etc/passwd or wp-config.php in parameter values.visual-portfolio plugin endpoints with unusual file path strings in query parameters or POST bodies; HTTP 200 responses to such requests may indicate successful LFI.wp-config.php) may result in unauthorized admin logins or new admin user creation.wp-config.php originating from unfamiliar IP addresses.The vendor has released version 3.5.2 of the Visual Portfolio, Photo Gallery & Post Grid plugin, which resolves this vulnerability. Site administrators should update the plugin immediately via the WordPress dashboard or manually. Patchstack users benefit from an automatically deployed virtual patch (mitigation rule) that blocks exploitation attempts without requiring an immediate plugin update. Sites with open user registration should consider temporarily disabling registration or restricting Subscriber-level access until the patch is applied (Patchstack).
Wordfence included this vulnerability in their weekly WordPress vulnerability report covering March 16–22, 2026, and Sucuri referenced it in their March 2026 vulnerability patch roundup, indicating broad coverage within the WordPress security community (Wordfence Blog, Sucuri Blog). The vulnerability was also noted on Mastodon via The Hacker Wire, reflecting general community awareness. No extraordinary controversy or vendor dispute has been reported.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."