PHP to Page <= 0.3 - Authenticated (Subscriber+) Local File Inclusion to Remote Code Execution via Shortcode
criticalThe PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and including, 0.3 via the 'php-to-page' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to include local file and potentially execute code on the server. While...
- CVSS:
- 9.9
- Affected:
- up to 0.3
- Fix:
- No patched version reported
- Disclosed:
- Oct 29, 2023