Local File Inclusion Vulnerability in Post Grid, Slider & Carousel Ultimate Plugin by WordPress
CVE-2024-13408

8.8HIGH

Key Information:

Vendor
WPwax
Status
Post Grid, Slider & Carousel Ultimate – With Shortcode, Gutenberg Block & Elementor Widget
Vendor
CVE Published:
24 January 2025

Summary

The Post Grid, Slider & Carousel Ultimate plugin for WordPress is susceptible to Local File Inclusion via the 'theme' attribute of the pgcu shortcode. This vulnerability impacts all versions up to and including 1.6.10. Authenticated users with Contributor-level access or higher can exploit this flaw to include and execute arbitrary files on the server, potentially allowing them to execute malicious PHP code. This exploitation can lead to unauthorized access to sensitive information, abuse of access controls, and remote code execution, particularly if attackers manage to upload PHP files that can be included maliciously.

Affected Version(s)

Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget * <= 1.6.10

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Djaidja Moundjid
.