Vulnerability Details CVE-2024-6164
The Filter & Grids WordPress plugin before 2.8.33 is vulnerable to Local File Inclusion via the post_layout parameter. This makes it possible for an unauthenticated attacker to include and execute PHP files on the server, allowing the execution of any PHP code in those files.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.04
EPSS Ranking 88.0%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2024-6164
-
cpe:2.3:a:ymc-22:filter_&_grids:1.2.0
-
cpe:2.3:a:ymc-22:filter_&_grids:1.2.2
-
cpe:2.3:a:ymc-22:filter_&_grids:1.2.3
-
cpe:2.3:a:ymc-22:filter_&_grids:1.2.4
-
cpe:2.3:a:ymc-22:filter_&_grids:1.2.5
-
cpe:2.3:a:ymc-22:filter_&_grids:1.2.6
-
cpe:2.3:a:ymc-22:filter_&_grids:1.2.7
-
cpe:2.3:a:ymc-22:filter_&_grids:1.2.8
-
cpe:2.3:a:ymc-22:filter_&_grids:1.2.9
-
cpe:2.3:a:ymc-22:filter_&_grids:1.3.0
-
cpe:2.3:a:ymc-22:filter_&_grids:1.3.1
-
cpe:2.3:a:ymc-22:filter_&_grids:2.1.0
-
cpe:2.3:a:ymc-22:filter_&_grids:2.1.1
-
cpe:2.3:a:ymc-22:filter_&_grids:2.1.2
-
cpe:2.3:a:ymc-22:filter_&_grids:2.1.3
-
cpe:2.3:a:ymc-22:filter_&_grids:2.1.4
-
cpe:2.3:a:ymc-22:filter_&_grids:2.1.5
-
cpe:2.3:a:ymc-22:filter_&_grids:2.2.1
-
cpe:2.3:a:ymc-22:filter_&_grids:2.2.4
-
cpe:2.3:a:ymc-22:filter_&_grids:2.2.5
-
cpe:2.3:a:ymc-22:filter_&_grids:2.3.1
-
cpe:2.3:a:ymc-22:filter_&_grids:2.3.10
-
cpe:2.3:a:ymc-22:filter_&_grids:2.3.11
-
cpe:2.3:a:ymc-22:filter_&_grids:2.3.13
-
cpe:2.3:a:ymc-22:filter_&_grids:2.3.15
-
cpe:2.3:a:ymc-22:filter_&_grids:2.3.16
-
cpe:2.3:a:ymc-22:filter_&_grids:2.3.17
-
cpe:2.3:a:ymc-22:filter_&_grids:2.3.18
-
cpe:2.3:a:ymc-22:filter_&_grids:2.3.19
-
cpe:2.3:a:ymc-22:filter_&_grids:2.3.2
-
cpe:2.3:a:ymc-22:filter_&_grids:2.3.21
-
cpe:2.3:a:ymc-22:filter_&_grids:2.3.3
-
cpe:2.3:a:ymc-22:filter_&_grids:2.3.4
-
cpe:2.3:a:ymc-22:filter_&_grids:2.3.5
-
cpe:2.3:a:ymc-22:filter_&_grids:2.3.6
-
cpe:2.3:a:ymc-22:filter_&_grids:2.3.7
-
cpe:2.3:a:ymc-22:filter_&_grids:2.3.8
-
cpe:2.3:a:ymc-22:filter_&_grids:2.3.9
-
cpe:2.3:a:ymc-22:filter_&_grids:2.4.1
-
cpe:2.3:a:ymc-22:filter_&_grids:2.4.3
-
cpe:2.3:a:ymc-22:filter_&_grids:2.4.5
-
cpe:2.3:a:ymc-22:filter_&_grids:2.4.6
-
cpe:2.3:a:ymc-22:filter_&_grids:2.4.9
-
cpe:2.3:a:ymc-22:filter_&_grids:2.5.1
-
cpe:2.3:a:ymc-22:filter_&_grids:2.5.10
-
cpe:2.3:a:ymc-22:filter_&_grids:2.5.11
-
cpe:2.3:a:ymc-22:filter_&_grids:2.5.3
-
cpe:2.3:a:ymc-22:filter_&_grids:2.5.4
-
cpe:2.3:a:ymc-22:filter_&_grids:2.5.6
-
cpe:2.3:a:ymc-22:filter_&_grids:2.5.8
-
cpe:2.3:a:ymc-22:filter_&_grids:2.5.9
-
cpe:2.3:a:ymc-22:filter_&_grids:2.6.1
-
cpe:2.3:a:ymc-22:filter_&_grids:2.6.10
-
cpe:2.3:a:ymc-22:filter_&_grids:2.6.13
-
cpe:2.3:a:ymc-22:filter_&_grids:2.6.14
-
cpe:2.3:a:ymc-22:filter_&_grids:2.6.16
-
cpe:2.3:a:ymc-22:filter_&_grids:2.6.17
-
cpe:2.3:a:ymc-22:filter_&_grids:2.6.19
-
cpe:2.3:a:ymc-22:filter_&_grids:2.6.2
-
cpe:2.3:a:ymc-22:filter_&_grids:2.6.20
-
cpe:2.3:a:ymc-22:filter_&_grids:2.6.22
-
cpe:2.3:a:ymc-22:filter_&_grids:2.6.3
-
cpe:2.3:a:ymc-22:filter_&_grids:2.6.4
-
cpe:2.3:a:ymc-22:filter_&_grids:2.7.1
-
cpe:2.3:a:ymc-22:filter_&_grids:2.7.2
-
cpe:2.3:a:ymc-22:filter_&_grids:2.7.3
-
cpe:2.3:a:ymc-22:filter_&_grids:2.7.4
-
cpe:2.3:a:ymc-22:filter_&_grids:2.7.5
-
cpe:2.3:a:ymc-22:filter_&_grids:2.8.1
-
cpe:2.3:a:ymc-22:filter_&_grids:2.8.10
-
cpe:2.3:a:ymc-22:filter_&_grids:2.8.13
-
cpe:2.3:a:ymc-22:filter_&_grids:2.8.15
-
cpe:2.3:a:ymc-22:filter_&_grids:2.8.18
-
cpe:2.3:a:ymc-22:filter_&_grids:2.8.19
-
cpe:2.3:a:ymc-22:filter_&_grids:2.8.20
-
cpe:2.3:a:ymc-22:filter_&_grids:2.8.23
-
cpe:2.3:a:ymc-22:filter_&_grids:2.8.24
-
cpe:2.3:a:ymc-22:filter_&_grids:2.8.25
-
cpe:2.3:a:ymc-22:filter_&_grids:2.8.29
-
cpe:2.3:a:ymc-22:filter_&_grids:2.8.31
-
cpe:2.3:a:ymc-22:filter_&_grids:2.8.32
-
cpe:2.3:a:ymc-22:filter_&_grids:2.8.4
-
cpe:2.3:a:ymc-22:filter_&_grids:2.8.6
-
cpe:2.3:a:ymc-22:filter_&_grids:2.8.8
-
cpe:2.3:a:ymc-22:filter_&_grids:2.8.9