CVE-2024-12859
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-12859 is a vulnerability affecting the BoomBox Theme Extensions plugin for WordPress. This issue allows authenticated attackers with contributor-level permissions and above to execute arbitrary PHP code through a Local File Inclusion vulnerability in the 'boombox_listing' shortcode's 'type' attribute. The vulnerability exists in all versions up to and including 1.8.0, posing a significant risk for bypassing access controls, obtaining sensitive data, and achieving code execution. Attackers can exploit this weakness to include and execute any PHP file they choose, potentially leading to serious security implications.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.