CVE-2024-49690: WordPress Qi Blocks plugin <= 1.3.2 - Local File Inclusion vulnerability
Published Oct 23, 2024
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Qode Qi Blocks qi-blocks.This issue affects Qi Blocks: from n/a through <= 1.3.2.
Affected Software
3 affected components
Qode Interactive Qi Blocks>=n/a<1.3.2
WordPress Qi Blocks<=1.3.2
Qodeinteractive Qi Blocks Wordpress<1.3.3
Remediation
Information
Update to 1.3.3 or a higher version.
Event History
Oct 23, 2024
CVE Published
via MITRE·03:16 PM
Data Sourced
via MITRE·03:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-49690?
CVE-2024-49690 has a critical severity rating due to its potential for remote file inclusion in affected versions of Qi Blocks.
2
How do I fix CVE-2024-49690?
To fix CVE-2024-49690, update Qi Blocks to the latest version or apply the relevant security patches immediately.
3
Which versions of Qi Blocks are affected by CVE-2024-49690?
CVE-2024-49690 affects all versions of Qi Blocks from n/a to 1.3.2.
4
What kind of attack does CVE-2024-49690 enable?
CVE-2024-49690 enables attackers to execute arbitrary code through remote file inclusion due to improper control of include statements.
5
Is the CVE-2024-49690 vulnerability present in WordPress installations?
Yes, CVE-2024-49690 is present in WordPress installations using the Qi Blocks plugin up to version 1.3.2.