Porto theme vulnerable to Local File Inclusion
CVE-2024-3807
What is CVE-2024-3807?
The Porto theme for WordPress contains a vulnerability that allows authenticated attackers, with contributor-level permissions and above, to perform Local File Inclusion (LFI) attacks. This vulnerability is triggered through the 'porto_page_header_shortcode_type', 'slideshow_type', and 'post_layout' post meta parameters, which enable the inclusion and execution of arbitrary files on the server. If exploited, attackers can bypass access controls, gain unauthorized access to sensitive data, and execute any PHP code contained within the included files. While this vulnerability was partially addressed in version 7.1.0, it received a full patch in version 7.1.1.
Affected Version(s)
Porto * <= 7.1.0
References
EPSS Score
6% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved