CVE-2026-32369: WordPress Medilink-Core plugin < 2.0.7 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Medilink-Core medilink-core allows PHP Local File Inclusion.This issue affects Medilink-Core: from n/a through < 2.0.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32369?
CVE-2026-32369 is classified as a high severity vulnerability due to its potential for local file inclusion that could lead to code execution.
How do I fix CVE-2026-32369?
To fix CVE-2026-32369, update the Medilink-Core plugin to version 2.0.7 or later.
What types of applications are affected by CVE-2026-32369?
CVE-2026-32369 affects the RadiusTheme Medilink-Core plugin versions earlier than 2.0.7.
Can CVE-2026-32369 be exploited remotely?
Yes, CVE-2026-32369 can be exploited remotely under certain conditions due to its nature as a local file inclusion vulnerability.
What are the potential consequences of exploiting CVE-2026-32369?
Exploitation of CVE-2026-32369 could allow an attacker to include and execute arbitrary files on the server, leading to significant security breaches.