CVE-2024-13790
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Mar 19, 2025
CWE ID 98
Summary
CVE-2024-13790 is a newly disclosed vulnerability affecting the MinimogWP eCommerce WordPress Theme. This issue, present in versions up to 3.7.0, permits unauthenticated attackers to execute arbitrary PHP code via a Local File Inclusion vulnerability through the 'template' parameter. By including and executing arbitrary files on the server, attackers can bypass access controls, obtain sensitive data, or achieve code execution, posing a significant threat to websites utilizing this theme.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.