PoC Index

CVE-2024-6459

CRITICAL 9.8EPSS 1.0%

The News Element Elementor Blog Magazine WordPress plugin before 1.0.6 is vulnerable to Local File Inclusion via the template parameter. This makes it possible for unauthenticated attacker to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.02% chance of exploitation in the next 30 days, 61th percentile
Published
2024-08-17
Updated
2024-09-13

Proof-of-concept exploits (1)

References

Related