CVE-2024-3808
The Porto Theme - Functionality plugin through version 3.1.0 contains a local file inclusion vulnerability in the 'porto_portfolios' shortcode's 'portfolio_layout' attribute that allows authenticated users with contributor access or higher to include and execute arbitrary files from the server. An attacker exploiting this flaw could run arbitrary PHP code, potentially gaining unauthorized access to sensitive information or achieving remote code execution if they can upload PHP files to the system. This vulnerability affects all versions up to and including 3.1.0, with remediation available in version 3.1.1 or later.
Based on public CVE data (MITRE/NVD).