S4E just found an informational finding from tcp full port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2023-5815

9.8
CVSShigh
Exploitable remotely over the internet · no authentication required.
Description

The News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry) plugin for WordPress is vulnerable to Remote Code Execution via Local File Inclusion in all versions up to, and including, 3.4.1 via the bdp_get_more_post function hooked via a nopriv AJAX. This is due to function utilizing an unsafe extract() method to extract values from the POST variable and passing that input to the include() function. This makes it possible for unauthenticated attackers to include arbitrary PHP files and achieve remote code execution. On vulnerable Docker configurations it may be possible for an attacker to create a PHP file and then subsequently include it to achieve RCE.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
blog designer pack – blog, post grid, post slider, post carousel, category post, newsnews_\&_blog_designer_pack_wordpress_blog_plugin
Updated Sep 28, 2026View on NVD →
S4E scanner

CVE history: blog designer pack – blog, post grid, post slider, post carousel, category post, news

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →