File Upload Vulnerability in VibeThemes WPLMS Plugin
CVE-2024-56052

9.9CRITICAL

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
18 December 2024

What is CVE-2024-56052?

The VibeThemes WPLMS plugin suffers from a vulnerability that allows an attacker to upload malicious files to the web server without proper authorization. This flaw can lead to the installation of web shells or other malicious scripts, compromising the security of the affected site. It specifically affects WPLMS versions prior to 1.9.9.5.2, offering a vector for attackers to exploit if not patched. Site administrators are strongly urged to update to the latest version to safeguard against potential exploit scenarios.

Affected Version(s)

WPLMS 0 <= 1.9.9.5.2

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

.