CVE-2025-46454 HIGH

CVE-2025-46454: WordPress Meta Keywords & Description plugin <= 0.8 - Local File Inclusion Vulnerability

Vendor Svil4Ok
Product Meta Keywords & Description
Weakness CWE-98 · PHP file inclusion
Published May 23, 2025
Last update April 28, 2026

CVSS base score

7.5/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in svil4ok Meta Keywords & Description wp-meta-keywords-meta-description allows PHP Local File Inclusion.This issue affects Meta Keywords & Description: from n/a through <= 0.8.

Explanation of Vulnerability in Simple Terms

02Summary

Meta Keywords & Description versions 0.8 and earlier contain a code injection vulnerability. An attacker can craft a malicious input that executes arbitrary code when a site administrator interacts with the plugin. The vulnerability requires the attacker to trick an admin into clicking a link or visiting a page, but once triggered, allows full control over the site.

What an attacker can do

03Attacker Capabilities

Execute arbitrary code on the site by tricking an admin into clicking a malicious link.

Potential impact on your site

04Site Impact

Attackers can run malicious code with admin privileges, potentially stealing data, modifying content, or taking over the site.

Conditions required to exploit

05Prerequisites

Site admin must click attacker-supplied link or visit attacker-controlled page; no prior authentication needed.

Key dates

06Disclosure timeline

May 23, 2025 CVE published
April 28, 2026 Record updated