Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h789-vxpj-rq4h

Опубликовано: 25 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

The Verdure Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

The Verdure Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

8.1 High

CVSS3

Дефекты

CWE-98

Связанные уязвимости

nvd
28 дней назад

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

8.1 High

CVSS3

Дефекты

CWE-98