Salient Core plugin vulnerable to Local File Inclusion in WordPress
CVE-2024-3812
What is CVE-2024-3812?
The Salient Core plugin for WordPress is susceptible to a Local File Inclusion vulnerability present in all versions up to and including 2.0.7. This vulnerability arises due to the 'nectar_icon' shortcode's 'icon_linea' attribute, enabling authenticated attackers with contributor-level permissions or higher to incorporate and execute arbitrary files on the server. The implications of this vulnerability are significant; attackers can exploit this flaw to bypass access controls, access sensitive information, and execute unauthorized PHP code, thus posing a serious risk to the integrity and confidentiality of the server's data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Salient Core * <= 2.0.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved