8.8
CVSSv3

CVE-2024-12859

CVSSv4: NA | CVSSv3: 8.8 | CVSSv2: NA | VMScore: 980 | EPSS: 0.00131 | KEV: Not Included
Published: 03/02/2025 Updated: 03/02/2025

Vulnerability Summary

Local File Inclusion in WordPress BoomBox Theme Extensions Plugin via Shortcode

The BoomBox Theme Extensions plugin for WordPress has a Local File Inclusion vulnerability in versions up to and including 1.8.0. The vulnerability exists in the 'boombox_listing' shortcode's 'type' attribute. An authenticated attacker with contributor-level or higher permissions can potentially include and execute arbitrary files on the server. This security issue allows attackers to bypass access controls, access sensitive data, and potentially execute PHP code if PHP file uploads are permitted. The vulnerability presents a significant risk to WordPress sites using this plugin, as it enables unauthorized file inclusion and execution.

Vulnerable Product Search on Vulmon Subscribe to Product

px-lab boombox theme extensions