What the vulnerability does
01Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in GravityWP GravityWP - Merge Tags gravitywp-merge-tags allows PHP Local File Inclusion.This issue affects GravityWP - Merge Tags: from n/a through <= 1.4.4.
Explanation of Vulnerability in Simple Terms
02Summary
GravityWP Merge Tags versions 1.4.4 and earlier contain a vulnerability that allows an attacker to execute arbitrary code on the site. The attack requires user interaction—typically a site administrator must visit a malicious link or page. An attacker with no prior authentication can exploit this to gain full control of the WordPress installation.
What an attacker can do
03Attacker Capabilities
Run arbitrary code on the site and take full control of the WordPress installation.
Potential impact on your site
04Site Impact
Complete compromise of your WordPress site, including data theft, malware installation, and loss of site control.
Conditions required to exploit
05Prerequisites
An authenticated admin or site user must visit a malicious link or page crafted by the attacker.
Key dates
06Disclosure timeline
August 14, 2025
CVE published
May 12, 2026
Record updated