CVE-2024-56042: WordPress WPLMS plugin < 1.9.9.5.3 - Unauthenticated SQL Injection vulnerability
Published Dec 31, 2024
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplmsplugin allows SQL Injection.This issue affects WPLMS: from n/a through < 1.9.9.5.3.
Affected Software
3 affected components
VibeThemes WPLMS<1.9.9.5.3
WordPress WPLMS plugin<1.9.9.5.3
VibeThemes Wordpress Learning Management System Wordpress<1.9.9.5.3
Remediation
Information
Update the WordPress WPLMS plugin to the latest available version (at least 1.9.9.5.3).
Event History
Dec 31, 2024
CVE Published
via MITRE·12:57 PM
Data Sourced
via MITRE·12:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-56042?
CVE-2024-56042 is classified as a high-severity SQL injection vulnerability affecting VibeThemes WPLMS.
2
How do I fix CVE-2024-56042?
To fix CVE-2024-56042, upgrade VibeThemes WPLMS to version 1.9.9.5.3 or later.
3
Which versions are affected by CVE-2024-56042?
CVE-2024-56042 affects WPLMS versions prior to 1.9.9.5.3.
4
Is CVE-2024-56042 exploitable?
Yes, CVE-2024-56042 is exploitable, allowing attackers to perform SQL injection attacks.
5
What systems are impacted by CVE-2024-56042?
CVE-2024-56042 impacts systems running VibeThemes WPLMS and the WordPress WPLMS plugin versions before 1.9.9.5.3.