CVE-2026-84069: Unknown Webfacing

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The WebFacing™ WordPress plugin before 5.4 does not restrict access to one of its bundled scripts and does not validate a user-supplied path before using it to include a local file, allowing unauthenticated users to perform Local File Inclusion.

Affected products

  • Unknown Webfacing: from 5.3, before 5.4 (fixed in 5.4)

Published 2026-09-27. Last modified 2026-09-28.