First published: Tue Jan 07 2025(Updated: )
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodeMShop 워드프레스 결제 심플페이 allows PHP Local File Inclusion.This issue affects 워드프레스 결제 심플페이: from n/a through 5.2.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Codemshop Mshop My Site | <=5.2.0 | |
WordPress 워드프레스 결제 심플페이 – 우커머스 결제 플러그인 | <=5.2.0 |
Update the WordPress 워드프레스 결제 심플페이 plugin to the latest available version (at least 5.2.2).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-56281 has been classified as a critical vulnerability due to its potential for remote file inclusion attacks.
To fix CVE-2024-56281, update CodeMShop 워드프레스 결제 심플페이 to the latest version beyond 5.2.0.
CVE-2024-56281 affects CodeMShop 워드프레스 결제 심플페이 versions 5.2.0 and earlier.
CVE-2024-56281 is classified as a PHP Local File Inclusion vulnerability.
Yes, CVE-2024-56281 can be exploited remotely, allowing attackers to include unauthorized files on the server.