CVE-2023-5250: Grid Plus <= 1.3.3 - Authenticated (Subscriber+) Local File Inclusion via Shortcode
The Grid Plus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.3 via a shortcode attribute. This allows subscriber-level, and above, attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files with arbitrary content can be uploaded and included.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability identified with CVE-2023-5250?
The vulnerability identified with CVE-2023-5250 is a Local File Inclusion vulnerability in the Grid Plus plugin for WordPress.
What is the severity level of CVE-2023-5250?
The severity level of CVE-2023-5250 is high with a severity value of 8.8.
What is the affected software and version for CVE-2023-5250?
The affected software is the Grid Plus plugin for WordPress up to and including version 1.3.2.
How can an attacker exploit CVE-2023-5250?
An attacker can exploit CVE-2023-5250 by using a shortcode attribute to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files.
Are there any references for CVE-2023-5250?
Yes, you can refer to the following links for more information: [link1](https://www.wordfence.com/threat-intel/vulnerabilities/id/a6407792-2c76-4149-a9f9-d53002135bec?source=cve), [link2](https://plugins.trac.wordpress.org/browser/grid-plus/tags/1.3.2/core/grid.plus.base.class.php#L19)