CVE-2026-48972: WordPress SeedProd Pro plugin < 6.19.5 - Local File Inclusion vulnerability
Published May 27, 2026
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SeedProd LLC SeedProd Pro allows PHP Local File Inclusion.
This issue affects SeedProd Pro: from n/a before 6.19.5.
Affected Software
1 affected component
SeedProd SeedProd Pro<6.19.5
Remediation
Information
Update the WordPress SeedProd Pro Plugin to the latest available version (at least 6.19.5).
Event History
May 27, 2026
CVE Published
via MITRE·01:20 PM
Data Sourced
via MITRE·01:20 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-48972?
The severity of CVE-2026-48972 is rated as high, with a score of 7.5.
2
How do I fix CVE-2026-48972?
You can fix CVE-2026-48972 by updating the WordPress SeedProd Pro Plugin to the latest version, at least 6.19.5.
3
What type of vulnerability is CVE-2026-48972?
CVE-2026-48972 is classified as a Local File Inclusion vulnerability.
4
Who is affected by CVE-2026-48972?
CVE-2026-48972 affects users of the SeedProd Pro plugin prior to version 6.19.5.
5
What are the potential impacts of CVE-2026-48972?
Exploitation of CVE-2026-48972 could allow an attacker to include and execute arbitrary files on the server.