CVE · High

CVE-2024-3808 — Porto Functionality [porto-functionality] < 3.1.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-3808 Porto Functionality [porto-functionality] < 3.1.1 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') High 8.8 < 3.1.1 3.1.1 2024-05-08

CVE-2024-3808

The Porto Theme - Functionality plugin through version 3.1.0 contains a local file inclusion vulnerability in the 'porto_portfolios' shortcode's 'portfolio_layout' attribute that allows authenticated users with contributor access or higher to include and execute arbitrary files from the server. An attacker exploiting this flaw could run arbitrary PHP code, potentially gaining unauthorized access to sensitive information or achieving remote code execution if they can upload PHP files to the system. This vulnerability affects all versions up to and including 3.1.0, with remediation available in version 3.1.1 or later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.