CVE-2024-13790

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 19, 2025
CWE ID 98

Summary

CVE-2024-13790 is a newly disclosed vulnerability affecting the MinimogWP eCommerce WordPress Theme. This issue, present in versions up to 3.7.0, permits unauthenticated attackers to execute arbitrary PHP code via a Local File Inclusion vulnerability through the 'template' parameter. By including and executing arbitrary files on the server, attackers can bypass access controls, obtain sensitive data, or achieve code execution, posing a significant threat to websites utilizing this theme.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share