Salient Core plugin vulnerable to Local File Inclusion in WordPress
CVE-2024-3812

7.5HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
18 May 2024

Summary

The Salient Core plugin for WordPress is susceptible to a Local File Inclusion vulnerability present in all versions up to and including 2.0.7. This vulnerability arises due to the 'nectar_icon' shortcode's 'icon_linea' attribute, enabling authenticated attackers with contributor-level permissions or higher to incorporate and execute arbitrary files on the server. The implications of this vulnerability are significant; attackers can exploit this flaw to bypass access controls, access sensitive information, and execute unauthorized PHP code, thus posing a serious risk to the integrity and confidentiality of the server's data.

Affected Version(s)

Salient Core * <= 2.0.7

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

István Márton
.