Local File Inclusion Vulnerability in Post Grid, Slider & Carousel Ultimate Plugin by WordPress
CVE-2024-13408
Key Information:
- Vendor
- WPwax
- Status
- Post Grid, Slider & Carousel Ultimate – With Shortcode, Gutenberg Block & Elementor Widget
- Vendor
- CVE Published:
- 24 January 2025
Summary
The Post Grid, Slider & Carousel Ultimate plugin for WordPress is susceptible to Local File Inclusion via the 'theme' attribute of the pgcu
shortcode. This vulnerability impacts all versions up to and including 1.6.10. Authenticated users with Contributor-level access or higher can exploit this flaw to include and execute arbitrary files on the server, potentially allowing them to execute malicious PHP code. This exploitation can lead to unauthorized access to sensitive information, abuse of access controls, and remote code execution, particularly if attackers manage to upload PHP files that can be included maliciously.
Affected Version(s)
Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget * <= 1.6.10
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved