Input validation vulnerability in News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry) 3.4.1

The News & Blog Designer Pack – WordPress Blog Plugin is a plugin for WordPress websites that allows users to design their blog posts. Unfortunately, it has been discovered that all versions of the plugin up to and including 3.4.1 contain a vulnerability that allows unauthorised attackers to run code on the WordPress website. This vulnerability is known as Remote Code Execution via Local File Inclusion. It is caused by the plugin not filtering the input it receives from attackers, meaning that attackers can include malicious files. On certain WordPress configurations, this can allow attackers to gain full control of the website.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.