The Filter & Grids WordPress plugin before 2.8.33 is...
Critical severity
Unreviewed
Published
Jul 18, 2024
to the GitHub Advisory Database
•
Updated Aug 22, 2024
Description
Published by the National Vulnerability Database
Jul 18, 2024
Published to the GitHub Advisory Database
Jul 18, 2024
Last updated
Aug 22, 2024
The Filter & Grids WordPress plugin before 2.8.33 is vulnerable to Local File Inclusion via the post_layout parameter. This makes it possible for an unauthenticated attacker to include and execute PHP files on the server, allowing the execution of any PHP code in those files.
References