CVE-2024-5577 is a critical Remote File Inclusion vulnerability affecting the Where I Was, Where I Will Be WordPress plugin, specifically in versions 1.1.1 and below. This flaw allows unauthenticated attackers to remotely include and execute arbitrary PHP code from external servers by manipulating the WIW_HEADER parameter in the /system/include/include_user.php file. While the vulnerability requires the uncommon 'allow_url_include' PHP setting to be enabled, successful exploitation could lead to complete system compromise, including bypassing access controls, data theft, and arbitrary code execution. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Mcnardelli | Where I Was, Where I Will Be | >= 0, <= 1.1.1CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.