First published: Wed Dec 18 2024(Updated: )
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a before 1.9.9.5.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPLMS | <1.9.9.5.2 | |
WPLMS | <1.9.9.5.2 |
Update the WordPress WPLMS plugin to the latest available version (at least 1.9.9.5.2).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-56057 is classified as a high severity vulnerability due to its potential to allow unrestricted file uploads.
To fix CVE-2024-56057, update the VibeThemes WPLMS to version 1.9.9.5.2 or later.
The consequences of CVE-2024-56057 include the possibility of attackers uploading malicious files, such as web shells, to the server.
If you are using WPLMS versions prior to 1.9.9.5.2, your installation is vulnerable to CVE-2024-56057.
CVE-2024-56057 affects users of VibeThemes WPLMS versions below 1.9.9.5.2, including those using the WordPress WPLMS plugin.