CVE-2024-43261 CRITICAL

CVE-2024-43261: WordPress Compute Links plugin <= 1.2.1 - Remote File Inclusion vulnerability

Vendor Hamed Naderfar
Product Compute Links
Weakness CWE-98 · PHP file inclusion
Published August 19, 2024
Last update April 28, 2026

CVSS base score

9.6/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hamed Naderfar Compute Links allows PHP Remote File Inclusion.This issue affects Compute Links: from n/a through 1.2.1.

Explanation of Vulnerability in Simple Terms

02Summary

Compute Links version 1.2.1 and earlier contains a vulnerability that allows an attacker to execute arbitrary code on the site. The vulnerability requires user interaction—a victim must visit a malicious link or page. Once exploited, the attacker gains full control over the site, including the ability to read, modify, or delete data, and disrupt service.

What an attacker can do

03Attacker Capabilities

Run arbitrary code on the site and take full control of it.

Potential impact on your site

04Site Impact

Complete compromise of the site, including data theft, defacement, and service disruption.

Conditions required to exploit

05Prerequisites

A victim must click a malicious link or visit an attacker-controlled page.

Key dates

06Disclosure timeline

August 19, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE