CVE-2024-56053: WordPress WPLMS plugin < 1.9.9.5.3 - Instructor+ SQL Injection vulnerability
Published Dec 18, 2024
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplmsplugin allows SQL Injection.This issue affects WPLMS: from n/a through < 1.9.9.5.3.
Affected Software
3 affected components
VibeThemes WPLMS<1.9.9.5.3
WordPress WPLMS plugin<1.9.9.5.3
VibeThemes Wordpress Learning Management System Wordpress<1.9.9.5.3
Remediation
Information
Update the WordPress WPLMS plugin to the latest available version (at least 1.9.9.5.3).
Event History
Dec 18, 2024
CVE Published
via MITRE·06:58 PM
Data Sourced
via MITRE·06:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-56053?
CVE-2024-56053 is classified as a high-severity vulnerability due to its potential for SQL injection attacks.
2
How do I fix CVE-2024-56053?
To fix CVE-2024-56053, upgrade VibeThemes WPLMS to version 1.9.9.5.3 or later.
3
Which versions of WPLMS are affected by CVE-2024-56053?
CVE-2024-56053 affects versions of WPLMS prior to 1.9.9.5.3.
4
What type of vulnerability is CVE-2024-56053?
CVE-2024-56053 is an SQL Injection vulnerability resulting from improper neutralization of special elements in SQL commands.
5
What is the impact of CVE-2024-56053 on my website?
Exploiting CVE-2024-56053 can lead to unauthorized access to the database and manipulation of sensitive data.