CVE-2024-50457: WordPress Qode Essential Addons plugin <= 1.6.3 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Qode Qode Essential Addons qode-essential-addons.This issue affects Qode Essential Addons: from n/a through <= 1.6.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50457?
CVE-2024-50457 is classified as a critical vulnerability due to its potential for remote file inclusion in PHP programs.
How do I fix CVE-2024-50457?
To mitigate CVE-2024-50457, update the Qode Essential Addons to the latest version beyond 1.6.3.
What software is affected by CVE-2024-50457?
CVE-2024-50457 affects Qode Essential Addons versions up to and including 1.6.3.
What type of vulnerability is CVE-2024-50457?
CVE-2024-50457 is a PHP Remote File Inclusion vulnerability, resulting from improper control of filename for include/require statements.
What are the risks associated with CVE-2024-50457?
Exploitation of CVE-2024-50457 can allow attackers to execute arbitrary code on the server, leading to a full system compromise.