First published: Sat Nov 16 2024(Updated: )
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Business Directory Team by RadiusTheme Classified Listing classified-listing allows PHP Local File Inclusion.This issue affects Classified Listing: from n/a through 3.1.15.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
RadiusTheme Classified Listing | <=3.1.15.1 | |
WordPress Classified Listing | <=3.1.15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-52386 has been classified as a critical vulnerability due to its potential for remote file inclusion.
To fix CVE-2024-52386, update the RadiusTheme Classified Listing plugin to the latest version.
CVE-2024-52386 affects the RadiusTheme Classified Listing and WordPress Classified Listing plugins up to version 3.1.15.1.
Yes, CVE-2024-52386 can potentially lead to data breaches by allowing attackers to execute malicious scripts.
As of the last report, there is no confirmation of active exploitation of CVE-2024-52386 in the wild.