CVE-2024-56052: WordPress WPLMS plugin < 1.9.9.5.2 - Student+ Arbitrary File Upload vulnerability
Published Dec 18, 2024
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplmsplugin allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a through < 1.9.9.5.2.
Affected Software
3 affected components
VibeThemes WPLMS<1.9.9.5.2
WordPress WPLMS plugin<1.9.9.5.2
VibeThemes Wordpress Learning Management System Wordpress<1.9.9.5.2
Remediation
Information
Update the WordPress WPLMS plugin to the latest available version (at least 1.9.9.5.2).
Event History
Dec 18, 2024
CVE Published
via MITRE·06:55 PM
Data Sourced
via MITRE·06:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 8, 58279
Event
via MITRE·07:04 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-56052?
CVE-2024-56052 has been classified with a high severity due to the potential for a web shell to be uploaded to a web server.
2
How do I fix CVE-2024-56052?
To mitigate CVE-2024-56052, upgrade VibeThemes WPLMS to a version higher than 1.9.9.5.2.
3
What type of vulnerability is CVE-2024-56052?
CVE-2024-56052 is classified as an unrestricted file upload vulnerability.
4
What software is affected by CVE-2024-56052?
CVE-2024-56052 affects VibeThemes WPLMS versions prior to 1.9.9.5.2 and the WordPress WPLMS plugin below this version.
5
What kind of attack can CVE-2024-56052 enable?
CVE-2024-56052 can enable attackers to upload a web shell to the server, potentially allowing them to execute malicious commands.