CVE-2024-12859

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Feb 3, 2025
CWE ID 98

Summary

CVE-2024-12859 is a vulnerability affecting the BoomBox Theme Extensions plugin for WordPress. This issue allows authenticated attackers with contributor-level permissions and above to execute arbitrary PHP code through a Local File Inclusion vulnerability in the 'boombox_listing' shortcode's 'type' attribute. The vulnerability exists in all versions up to and including 1.8.0, posing a significant risk for bypassing access controls, obtaining sensitive data, and achieving code execution. Attackers can exploit this weakness to include and execute any PHP file they choose, potentially leading to serious security implications.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share