CVE-2026-28150: WordPress Golo Framework plugin < 1.7.5 - Local File Inclusion vulnerability
Published Aug 20, 2026
·Updated
Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions.
Affected Software
1 affected component
WordPress plugin/Golo Framework<1.7.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Golo Framework pluginto a version that resolves this vulnerability.Fixed in 1.7.5
Event History
Aug 20, 2026
CVE Published
via MITRE·12:06 PM
Data Sourced
via MITRE·12:06 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or other prior privileges. Exploitation is network-accessible, though the vector has high attack complexity.
2
Which versions require remediation?
Golo Framework versions earlier than 1.7.5 are affected. Update the plugin to version 1.7.5 or later.
3
What is the potential impact of successful exploitation?
The reported impact includes high confidentiality, integrity, and availability effects. Successful exploitation could therefore affect data disclosure, modification, and service availability.