CVE-2024-56216: WordPress Themify Builder plugin <= 7.6.3 - Local File Inclusion vulnerability
Published Dec 31, 2024
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themifyme Themify Builder themify-builder allows PHP Local File Inclusion.This issue affects Themify Builder: from n/a through <= 7.6.3.
Affected Software
3 affected components
Themify Builder WordPress<=7.6.3
Themify Themify Builder<=7.6.3
WordPress Themify Builder<=7.6.3
Remediation
Information
Update the WordPress Themify Builder plugin to the latest available version (at least 7.6.5).
Event History
Dec 31, 2024
CVE Published
via MITRE·09:59 AM
Data Sourced
via MITRE·09:59 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-56216?
CVE-2024-56216 is a high-severity vulnerability that allows PHP local file inclusion in Themify Builder.
2
How do I fix CVE-2024-56216?
To fix CVE-2024-56216, upgrade Themify Builder to version 7.6.4 or later.
3
What software is affected by CVE-2024-56216?
CVE-2024-56216 affects Themify Builder versions up to 7.6.3.
4
What kind of attacks can CVE-2024-56216 potentially allow?
CVE-2024-56216 can potentially allow attackers to access or include unauthorized files on the server.
5
Is CVE-2024-56216 exploitable without authentication?
Yes, CVE-2024-56216 can be exploited without authentication, making it particularly dangerous.