What the vulnerability does
01Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in svil4ok Meta Keywords & Description wp-meta-keywords-meta-description allows PHP Local File Inclusion.This issue affects Meta Keywords & Description: from n/a through <= 0.8.
Explanation of Vulnerability in Simple Terms
02Summary
Meta Keywords & Description versions 0.8 and earlier contain a code injection vulnerability. An attacker can craft a malicious input that executes arbitrary code when a site administrator interacts with the plugin. The vulnerability requires the attacker to trick an admin into clicking a link or visiting a page, but once triggered, allows full control over the site.
What an attacker can do
03Attacker Capabilities
Execute arbitrary code on the site by tricking an admin into clicking a malicious link.
Potential impact on your site
04Site Impact
Attackers can run malicious code with admin privileges, potentially stealing data, modifying content, or taking over the site.
Conditions required to exploit
05Prerequisites
Site admin must click attacker-supplied link or visit attacker-controlled page; no prior authentication needed.
Key dates
06Disclosure timeline
May 23, 2025
CVE published
April 28, 2026
Record updated