VYPR

Category Ajax Filter

by WordPress

Source repositories

CVEs (1)

  • CVE-2024-10871CriNov 9, 2024
    risk 0.57cvss 9.8epss 0.01

    The Category Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.2 via the 'params[caf-post-layout]' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server,…