What the vulnerability does
01Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Widget for Google Reviews business-reviews-wp allows PHP Local File Inclusion.This issue affects Widget for Google Reviews: from n/a through <= 1.0.15.
Explanation of Vulnerability in Simple Terms
02Summary
The Widget for Google Reviews plugin contains a vulnerability that allows an attacker to execute arbitrary code on affected sites. The flaw requires specific conditions to exploit but can result in complete compromise of the site, including unauthorized access to data and the ability to modify or delete content. All versions up to 1.0.15 are affected.
What an attacker can do
03Attacker Capabilities
Run their own code on the site and gain full control over it.
Potential impact on your site
04Site Impact
An attacker could steal data, modify pages, inject malware, or take the site offline without your knowledge.
Conditions required to exploit
05Prerequisites
Network access; no authentication or user interaction required, but exploitation requires specific technical conditions.
Key dates
06Disclosure timeline
August 20, 2025
CVE published
April 28, 2026
Record updated