The Filter & Grids WordPress plugin before 2.8.33 is vulnerable to Local File Inclusion via the post_layout parameter. This makes it possible for an unauthenticated attacker to include and execute PHP files on the server, allowing the execution of any PHP code in those files.
History

Thu, 22 Aug 2024 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Ymc-22
Ymc-22 filter \& Grids
Weaknesses CWE-22
CPEs cpe:2.3:a:ymc-22:filter_\&_grids:*:*:*:*:*:wordpress:*:*
Vendors & Products Ymc-22
Ymc-22 filter \& Grids

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-07-18T06:00:04.048Z

Updated: 2024-08-01T21:33:04.599Z

Reserved: 2024-06-19T14:33:57.257Z

Link: CVE-2024-6164

cve-icon Vulnrichment

Updated: 2024-08-01T21:33:04.599Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-18T06:15:02.233

Modified: 2024-08-22T16:35:18.693

Link: CVE-2024-6164

cve-icon Redhat

No data.