Local File Inclusion Vulnerability in WordPress Plugin
CVE-2026-27555
8.8HIGH
What is CVE-2026-27555?
A vulnerability has been identified within a WordPress plugin that allows an attacker with low privileges to exploit a local file inclusion flaw. By leveraging a valid user cookie, the attacker can gain access to the /index.php/ajax/get_iodd_port_info endpoint, leading to the potential execution of arbitrary PHP code on the affected device. This weakness poses significant risks, enabling unauthorized actions that could compromise system integrity and data security.
Affected Version(s)
ICE2-8IOL-G65L-V1D 1.0.0 < 1.7.4
ICE2-8IOL-K45P-RJ45 1.0.0 < 1.7.4
ICE2-8IOL-K45S-RJ45 1.0.0 < 1.7.4
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Gabriele Quagliarella from Nozomi Networks
Luca Borzacchiello from Nozomi Networks
