s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVE-2018-25329

📛 CVE Title

(no title)

Description

WordPress Plugin WP with Spritz 1.0 contains a remote file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting file paths into the url parameter. Attackers can send GET requests to wp.spritz.content.filter.php with malicious url values to access sensitive files like system configuration and credentials.

Overview

State
—
Assigner (CNA)
—
CVSS severity
high
CVSS score
CVSS 7.5 / 10 7.5 7.5 / 10
CVSS vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Effective score
7.5 / 10 HIGH source: CNA overview
CWE(s)
—
Reserved
—
Published
—
Last updated
—
Source
https://www.tenable.com/cve/CVE-2018-25329
Linked Threat
CVE-2018-25329 — WP with Spritz <= 1.0 - Unauthenticated Local File Inclusion

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2026-05-17 13:16:44 UTC
NVD last modified
2026-05-18 17:05:46 UTC
NVD CVSS v3.1
CVSS 7.5 / 10 7.5 7.5 / 10 HIGH source: disclosure@vulncheck.com
NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability subscore
3.9 / 10
Impact subscore
3.6 / 10
EPSS score
0.0004 (probability of exploitation in next 30 days)
EPSS percentile
11.88% vs all CVEs — higher = more likely to be exploited, as of 2026-06-03

NVD-assigned CWE(s): CWE-98 (differs from the CNA list above)

NVD / KEV / EPSS data refreshed 2026-06-03 19:54 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2018-21851
Assigner
VulnCheck
Published
May 17, 2026, 12:11:34 PM
Updated
May 18, 2026, 2:38:08 PM
EUVD base score (CVSS 4.0)
8.7 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EUVD-reported EPSS
0.0400
Vendors
wp-with-spritz
Products
WP with Spritz (1.0)
Aliases
GHSA-538v-9qx2-525c

ENISA description: WordPress Plugin WP with Spritz 1.0 contains a remote file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting file paths into the url parameter. Attackers can send GET requests to wp.spritz.content.filter.php with malicious url values to access sensitive files like system configuration and credentials.

EUVD references (3)

Vendor references (0)

References embedded in the original CVE record by the assigning CNA.

None in the CVE record.

Web references (6)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

NVD-tagged references (3)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Indicators (1)

IOCs linked to the auto-promoted Threat row.

TypeValueVirusTotalAttached
cve CVE-2018-25329 no local data 2026-07-30 02:53 UTC

Flagged vendors

    Remediations (11)

    Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

    • Wordfence remediation: WP with Spritz
      Wordfence

      No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.

      2026-07-30 02:53 UTC
    • web:documentation.n-able.com

      For more information on how Patch Manager provides third-party patching, see Patching third-party software. Use the table's InstallerURLs location when configuring vendor and patch exclusions in your firewalls and other web-monitoring software.

      2026-05-26 02:57 UTC
    • web:feedly.com

      15-Second summary Keeping up with Microsoft's Patch Tuesday releases is time-consuming for analysts, who need to assess vulnerabilities quickly, determine their relevance and criticality, and prioritize remediation—all while under pressure to protect their organizations. With Feedly's free Patch Tuesday report, you can: View charts breaking down the vulnerabilities by attack type and ...

      2026-05-26 02:57 UTC
    • web:freshysites.com

      Security Alert Summary The WP with Spritz plugin contains a remote file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting file paths into a URL parameter. Attackers can send specially crafted GET requests to a plugin PHP endpoint to access sensitive files such as system configuration and credentials. CVE Details CVE

      2026-05-26 02:57 UTC
    • web:nvd.nist.gov

      The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics. For ...

      2026-05-26 02:57 UTC
    • web:cybersecuritynews.com

      Microsoft released its March 2026 Patch Tuesday security update on March 10, 2026, addressing 78 vulnerabilities across Windows, Microsoft Office, Azure, SQL Server, and .NET. The update includes one actively exploited zero-day vulnerability and multiple Critical-rated flaws demanding immediate attention from security teams. The most urgent fix this month is CVE -2026-21262, the sole zero-day ...

      2026-05-26 02:57 UTC
    • web:support.esri.com

      BUG-000153493 - Installing ArcGIS Server Security 2022 Update 1 Patch or Update 2 Patch on ArcGIS Server 10.8.1 affects the access to existing Workflow Manager (Classic) feature services. BUG-000153438 - ArcGIS Server services folders become inaccessible in the REST endpoint if it has a dot (.) in the name and the Security patches are installed.

      2026-05-26 02:57 UTC
    • web:www.linkedin.com

      Microsoft has released its May 2026 Patch Tuesday security updates, addressing more than 130 vulnerabilities across its software ecosystem, including Windows, Microsoft Office, SharePoint Server ...

      2026-05-26 02:57 UTC
    • web:www.oracle.com

      This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.

      2026-05-26 02:57 UTC
    • web:www.tenable.com

      With another year of Patch Tuesday releases behind us, Microsoft has yet to break its 2020 record with 1,245 CVE's patched. However, this is the second year in a row that Microsoft crossed the 1,000 CVE threshold, and the third time since Patch Tuesday's inception. In 2025, Microsoft broke its record for the most CVEs patched in a month twice.

      2026-05-26 02:57 UTC
    • web:portal.msrc.microsoft.com

      The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

      2026-05-26 02:57 UTC

    AI Forensic Analysis

    Only Available for Registered Users. Sign in to view.

    Raw JSON

    The full cvelistV5 record. Download as CVE-2018-25329.json.

    Not stored.