🔐 CVE Alert

CVE-2026-32426

HIGH 7.5

WordPress Medilazar Core plugin < 1.4.7 - Local File Inclusion vulnerability

CVSS Score
7.5
EPSS Score
0.1%
EPSS Percentile
32th

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themelexus Medilazar Core medilazar-core allows PHP Local File Inclusion.This issue affects Medilazar Core: from n/a through < 1.4.7.

CWE CWE-98
Vendor themelexus
Product medilazar core
Published Mar 13, 2026
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for themelexus medilazar core

Be the first to know when new high vulnerabilities affecting themelexus medilazar core are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

themelexus / Medilazar Core
0 ≤ 1.4.7

References

NVD ↗ CVE.org ↗ EPSS Data ↗
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/medilazar-core/vulnerability/wordpress-medilazar-core-plugin-1-4-7-local-file-inclusion-vulnerability?_s_id=cve

Credits

João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program