CVE-2023-5815
WordPress vulnerability analysis and mitigation

Overview

The News & Blog Designer Pack WordPress plugin contains a critical Remote Code Execution (RCE) vulnerability tracked as CVE-2023-5815. The vulnerability affects all versions up to and including 3.4.1, allowing unauthenticated attackers to execute arbitrary code via Local File Inclusion through the bdpgetmore_post function. The vulnerability was discovered in October 2023 and affects over 30,000 WordPress installations (Security Online, NVD).

Technical details

The vulnerability exists in the bdpgetmore_post function which is hooked via a nopriv AJAX action. The function utilizes an unsafe extract() method to extract values from the POST variable and passes that input to the include() function. This implementation makes it possible for unauthenticated attackers to include arbitrary PHP files and achieve remote code execution. The vulnerability has received a CVSS v3.1 base score of 9.8 (CRITICAL) from NIST and 8.1 (HIGH) from Wordfence, indicating its severe nature (NVD).

Impact

The vulnerability allows unauthenticated attackers to execute arbitrary code on vulnerable websites. On vulnerable Docker configurations, attackers can create and subsequently include PHP files to achieve remote code execution, potentially leading to complete server compromise. With over 30,000 active installations, the impact of this vulnerability is significant (Security Online).

Mitigation and workarounds

Users are strongly advised to update to version 3.4.2 of the News & Blog Designer Pack plugin, which contains the security fix. If immediate update is not possible, it is recommended to disable the plugin until it can be updated (Security Online).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-13542CRITICAL9.8
  • designthemes-lms
NoYesDec 02, 2025
CVE-2025-13724HIGH7.5
  • vikrentcar
NoYesDec 02, 2025
CVE-2025-13731MEDIUM6.4
  • nexter-extension
NoYesDec 02, 2025
CVE-2025-12630MEDIUM4.9
  • upload-am-file-hosting-vpn
NoYesDec 02, 2025
CVE-2025-13090MEDIUM4.9
  • wpdirectorykit
NoYesDec 02, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management