The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via 'porto_page_header_shortcode_type', 'slideshow_type' and 'post_layout' post meta. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included. This was partially patched in version 7.1.0 and fully patched in version 7.1.1.
We have discovered 16,459 live websites that are affected by CVE-2024-3807.
Product | ![]() |
Category | Wordpress Themes |
Vulnerable Domains | 16,459 live websites (66.79% of Porto install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 300 versions ( 88.50% of all versions) |
![]() | 5,031 websites |
![]() | 1,622 websites |
![]() | 769 websites |
![]() | 758 websites |
![]() | 682 websites |
![]() | 569 websites |
![]() | 514 websites |
![]() | 431 websites |
![]() | 418 websites |
![]() | 382 websites |
.com | 6,775 websites |
.com.br | 692 websites |
.ru | 575 websites |
.co.uk | 414 websites |
.it | 385 websites |
.de | 372 websites |
.nl | 346 websites |
.org | 333 websites |
.net | 331 websites |
.pl | 265 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***.domains | ![]() | *,*** | |
***********************.com | ![]() | **,*** | |
**********.com | ![]() | **,*** | |
********.ir | ![]() | **,*** | |
***************.nl | ![]() | **,*** | |
****************.com | ![]() | ***,*** | |
*********.com | ![]() | ***,*** | |
***********.org | ![]() | ***,*** | |
**************************.de | ![]() | ***,*** | |
***********.com | ![]() | ***,*** |