CVE-2018-25329

HIGH

WordPress Plugin WP with Spritz 1.0 Remote File Inclusion

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-25329. PoCs published by Wadeek.

AI-analyzed exploit summary The exploit demonstrates a Remote File Inclusion (RFI) vulnerability in the WordPress plugin WP with Spritz 1.0. It leverages the 'url' parameter in 'wp.spritz.content.filter.php' to include arbitrary local or remote files, such as '/etc/passwd' or a remote shell script.

Description

WordPress Plugin WP with Spritz 1.0 contains a remote file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting file paths into the url parameter. Attackers can send GET requests to wp.spritz.content.filter.php with malicious url values to access sensitive files like system configuration and credentials.

Exploits (1)

exploitdb WORKING POC
by Wadeek · phpwebappsphp
https://www.exploit-db.com/exploits/44544

The exploit demonstrates a Remote File Inclusion (RFI) vulnerability in the WordPress plugin WP with Spritz 1.0. It leverages the 'url' parameter in 'wp.spritz.content.filter.php' to include arbitrary local or remote files, such as '/etc/passwd' or a remote shell script.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: WordPress Plugin WP with Spritz 1.0
No auth needed
Prerequisites: WordPress with WP with Spritz plugin version 1.0 installed
devstral-2 · analyzed May 17, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-44544
https://www.exploit-db.com/exploits/44544
Third Party Advisory third-party-advisory
VulnCheck Advisory: WordPress Plugin WP with Spritz 1.0 Remote File Inclusion
https://www.vulncheck.com/advisories/wordpress-plugin-wp-with-spritz-remote-file-inclusion

Scores

CVSS v3 7.5
EPSS 0.0040
EPSS Percentile 31.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-98
Status published
Products (1)
wp-with-spritz/WP with Spritz 1.0
Published May 17, 2026
Tracked Since May 17, 2026