CVE-2024-6460
Grow by Tradedoubler <= 2.0.21 - Unauthenticated LFI
- Published
- Aug 16, 2024
- Updated
- Sep 13, 2024
- Assigning CNA
- WPScan
- Evidence observed
- Aug 5, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HLow · next 30 days
- Percentile
- 91.6%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The Grow by Tradedoubler WordPress plugin through 2.0.21 is vulnerable to Local File Inclusion via the component parameter. This makes it possible for attackers to include and execute PHP files on the server, allowing the execution of any PHP code in those files.
Sources
2- CVE-2024-6460Exploit
备份的CVE
- CVE-2024-6460Exploit
Grow by Tradedoubler < 2.0.22 - Unauthenticated LFI
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.