Post Grid Master WordPress Plugin Local File Inclusion Vulnerability

Vulnerability

A local file inclusion vulnerability has been identified in the Post Grid Master WordPress plugin, specifically in versions through 3.4.12. The issue arises in the 'locate_template' function, where unauthenticated attackers can include and execute arbitrary PHP files on the server. This vulnerability could be exploited to bypass access controls, access sensitive information, or execute code, particularly if the server allows the upload and inclusion of files with certain extensions, such as images.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of PHP code on the server, potentially allowing attackers to bypass access controls, access sensitive data, or execute malicious actions, especially in scenarios where file uploads are permitted.

Reproduction

To reproduce this vulnerability, send a request to the WordPress site with the Post Grid Master plugin active, targeting the 'wp_ajax_asr_filter_posts' action. Include a payload that specifies a PHP file to be included via the 'locate_template' function. The server must be configured to allow the execution of PHP files in the specified location.

Remediation

No known patch is available. It is recommended to uninstall the affected plugin and consider a replacement.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
5.6
exploitability
8.6
remediation
0.0
relevance
0.0
threat
4.8
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.