CVE-2024-48029 | Hung Trang Si SB Random Posts Widget Plugin up to 1.0 on WordPress Include/Require filename control

A vulnerability classified as problematic has been found in Hung Trang Si SB Random Posts Widget Plugin up to 1.0 on WordPress. Affected is an unknown function of the component Include/Require. The manipulation leads to improper control of filename for include/require statement in php program (‘php remote file inclusion’).

This vulnerability is traded as CVE-2024-48029. It is possible to launch the attack remotely. There is no exploit available.