Local File Inclusion Vulnerability in BMLT Meeting Map Plugin for WordPress
CVE-2024-13593
8.8HIGH
What is CVE-2024-13593?
The BMLT Meeting Map plugin for WordPress is susceptible to Local File Inclusion (LFI) vulnerabilities, which impact all versions up to and including 2.6.0. This vulnerability allows authenticated attackers with Contributor-level access or higher to exploit the 'bmlt_meeting_map' shortcode. By including arbitrary files from the server, attackers can execute potentially malicious PHP code, bypassing access controls. This could lead to unauthorized data access, data leakage, or code execution via uploaded files that are deemed 'safe', such as images. Users of the affected plugin are strongly advised to upgrade to the latest version to mitigate this risk.
Affected Version(s)
BMLT Meeting Map * <= 2.6.0