Vulnerability in WP Blog Post Layouts Plugin Allows Arbitrary File Execution
CVE-2024-5503
What is CVE-2024-5503?
The WP Blog Post Layouts plugin for WordPress contains a Local File Inclusion vulnerability that affects all versions up to and including 1.1.3. Authenticated users with Contributor-level access or higher can exploit this vulnerability to include and execute arbitrary PHP files located on the server. This not only allows attackers to bypass access controls but also poses a significant risk by enabling access to sensitive data and potential code execution, especially when images and other seemingly 'safe' file types are involved in the upload and inclusion process.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WP Blog Post Layouts * <= 1.1.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved