Post Slides <= 1.0.1 - Contributor+ Local File Inclusion
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.5epss 0.3%
exploitation probability
0.3%top 81% of all CVEs
observed exploitation
nono source reports it
The Post Slides WordPress plugin through 1.0.1 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as with contributor or higher roles to perform LFI attacks
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
Affected products
Unknown · Post Slides