The News & Blog Designer Pack WordPress plugin up to version 3.4.1 contains a remote code execution caused by local file inclusion in the bdp_get_more_post function, letting unauthenticated attackers include arbitrary PHP files, exploit requires AJAX request with crafted POST data.
id: CVE-2023-5815
info:
name: News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauth
...