Local File Inclusion Vulnerability in BMLT Meeting Map Plugin for WordPress
CVE-2024-13593
7.5HIGH
Summary
The BMLT Meeting Map plugin for WordPress is susceptible to Local File Inclusion (LFI) vulnerabilities, which impact all versions up to and including 2.6.0. This vulnerability allows authenticated attackers with Contributor-level access or higher to exploit the 'bmlt_meeting_map' shortcode. By including arbitrary files from the server, attackers can execute potentially malicious PHP code, bypassing access controls. This could lead to unauthorized data access, data leakage, or code execution via uploaded files that are deemed 'safe', such as images. Users of the affected plugin are strongly advised to upgrade to the latest version to mitigate this risk.
Affected Version(s)
BMLT Meeting Map * <= 2.6.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Peter Thaleikis