The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.5.9 via several functions like penci_archive_more_post_ajax_func, penci_more_post_ajax_func, and penci_more_featured_post_ajax_func. This makes it possible for unauthenticated attackers to include and execute PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files can be uploaded and included. The exploitability of this is limited to Windows.
History

Fri, 06 Dec 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Pencidesign
Pencidesign soledad
CPEs cpe:2.3:a:pencidesign:soledad:*:*:*:*:*:wordpress:*:*
Vendors & Products Pencidesign
Pencidesign soledad
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 06 Dec 2024 09:30:00 +0000

Type Values Removed Values Added
Description The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.5.9 via several functions like penci_archive_more_post_ajax_func, penci_more_post_ajax_func, and penci_more_featured_post_ajax_func. This makes it possible for unauthenticated attackers to include and execute PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files can be uploaded and included. The exploitability of this is limited to Windows.
Title Soledad <= 8.5.9 - Unauthenticated Limited Local File Inclusion
Weaknesses CWE-98
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-12-06T17:10:29.065Z

Reserved: 2024-11-15T20:44:20.830Z

Link: CVE-2024-11289

cve-icon Vulnrichment

Updated: 2024-12-06T17:10:13.315Z

cve-icon NVD

Status : Received

Published: 2024-12-06T10:15:05.450

Modified: 2024-12-06T10:15:05.450

Link: CVE-2024-11289

cve-icon Redhat

No data.