sanitize_key of the file wp-config.php of the component AJAX Handler. Executing a manipulation of the argument wpfm_dir_path can lead to file inclusion.This vulnerability is registered as CVE-2026-8095. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
SOCIAL SHARE CARD GENERATOR