Include Me
Include Me has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 6.6, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include PHP Remote File Inclusion.
Every one of the 2 issues recorded for Include Me has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Include Me is installed on roughly 4,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2021-24453Include Me <= 1.2.1 - Local File Inclusion leading to Authenticated Remote Code Execution
Read the full analysisVulnerability Records

Include Me
Author
Stefano Lissa
Include Me helps to include in posts or pages external files usually to be shared between different posts or pages or that contains PHP or other code that can be compromised by the visual editor. The use is immediate: the shortcode [includeme] is all that you need (see the documentation on Include Me official page). The best way to use it is to include functionalities written in external PHP that will be rendered in post body or to include pieces of javascript that will be hard to add with WordPress editor. Inclusions can be rendered with IFRAME if needed to create boxes that display external web pages. This plugin is made of few line of code, ultralite! Other plugins by Stefano Lissa: Hyper Cache Newsletter Header and Footer Thumbnails Translation You can contribute to translate this plugin in your language on WordPress Translate
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C