Include Me

Include Me has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 6.6, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.

The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include PHP Remote File Inclusion.

Every one of the 2 issues recorded for Include Me has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Include Me is installed on roughly 4,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
6.6/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Include Me vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2021-24453

Include Me <= 1.2.1 - Local File Inclusion leading to Authenticated Remote Code Execution

Read the full analysis

Vulnerability Records

2 records
Include Me banner
Latestv1.3.7
4.8(21)
96/100
Last Updated
2026-02-05 (7mo ago)
Active Installs
4,000+
Downloads
94,056
Requires WP
6.1+
Requires PHP
7.0+
Tested up to
WP 6.9.7
Created
2010-04-27 (17y ago)

Include Me helps to include in posts or pages external files usually to be shared between different posts or pages or that contains PHP or other code that can be compromised by the visual editor. The use is immediate: the shortcode [includeme] is all that you need (see the documentation on Include Me official page). The best way to use it is to include functionalities written in external PHP that will be rendered in post body or to include pieces of javascript that will be hard to add with WordPress editor. Inclusions can be rendered with IFRAME if needed to create boxes that display external web pages. This plugin is made of few line of code, ultralite! Other plugins by Stefano Lissa: Hyper Cache Newsletter Header and Footer Thumbnails Translation You can contribute to translate this plugin in your language on WordPress Translate

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C