BoomBox Theme Extensions Local File Inclusion Vulnerability for WordPress
Vulnerability
A local file inclusion vulnerability has been identified in the BoomBox Theme Extensions plugin for WordPress, affecting all versions through 1.8.0. The vulnerability arises in the 'boombox_listing' shortcode, specifically within the 'type' attribute. This flaw allows authenticated attackers with contributor-level permissions or higher to include and execute arbitrary files on the server. Exploitation of this vulnerability could lead to the execution of PHP code contained in the included files, potentially bypassing access controls, accessing sensitive data, or executing code in scenarios where PHP files can be uploaded and included.
Impact
Exploitation of this vulnerability could result in unauthorized file inclusion, allowing attackers to execute arbitrary PHP code on the server. This could be used to bypass access controls, access sensitive information, or execute malicious code, especially if the uploaded PHP files can be included and executed on the server.
Remediation
Users are advised to update the BoomBox Theme Extensions plugin to version 1.8.1 or a later patched version.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
