CVE-2024-5456: Panda Video <= 1.4.0 - Authenticated (Contributor+) Local File Inclusion
The Panda Video plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.0 via the 'selectedbutton' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5456?
The severity of CVE-2024-5456 is considered high due to the potential for authenticated attackers to execute arbitrary files.
Who is affected by CVE-2024-5456?
CVE-2024-5456 affects users of the Panda Video plugin for WordPress, specifically those using versions up to and including 1.4.0.
How do I fix CVE-2024-5456?
To fix CVE-2024-5456, update the Panda Video plugin to the latest version that addresses this vulnerability.
What versions of Panda Video are vulnerable to CVE-2024-5456?
All versions of the Panda Video plugin up to and including 1.4.0 are vulnerable to CVE-2024-5456.
What type of vulnerability is CVE-2024-5456?
CVE-2024-5456 is a Local File Inclusion vulnerability that allows certain authenticated users to include and execute arbitrary files.