CVE-2024-56051: WordPress WPLMS plugin < 1.9.9.5 - Student+ Remote Code Execution (RCE) vulnerability
Published Dec 18, 2024
·Updated
Improper Control of Generation of Code ('Code Injection') vulnerability in VibeThemes WPLMS wplmsplugin allows Code Injection.This issue affects WPLMS: from n/a through < 1.9.9.5.
Affected Software
3 affected components
VibeThemes WPLMS<1.9.9.5
WordPress WPLMS plugin<1.9.9.5
VibeThemes Wordpress Learning Management System Wordpress<1.9.9.5
Remediation
Information
Update the WordPress WPLMS plugin to the latest available version (at least 1.9.9.5).
Event History
Dec 18, 2024
CVE Published
via MITRE·06:41 PM
Data Sourced
via MITRE·06:41 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-56051?
CVE-2024-56051 has a critical severity level due to its potential for code injection.
2
How do I fix CVE-2024-56051?
To fix CVE-2024-56051, you should update VibeThemes WPLMS to a version later than 1.9.9.5.
3
Which versions of WPLMS are affected by CVE-2024-56051?
CVE-2024-56051 affects all versions of WPLMS up to but not including version 1.9.9.5.
4
What type of vulnerability is CVE-2024-56051?
CVE-2024-56051 is classified as a Code Injection vulnerability.
5
Who can be impacted by CVE-2024-56051?
Users of VibeThemes WPLMS and the associated WordPress WPLMS plugin prior to version 1.9.9.5 are at risk of exploitation.