CVE-2024-56281: WordPress 워드프레스 결제 심플페이 – 우커머스 결제 플러그인 plugin <= 5.2.0 - Local File Inclusion vulnerability
Published Jan 7, 2025
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in codemstory 워드프레스 결제 심플페이 pgall-for-woocommerce allows PHP Local File Inclusion.This issue affects 워드프레스 결제 심플페이: from n/a through <= 5.2.0.
Affected Software
1 affected component
codemstory pgall-for-woocommerce (워드프레스 결제 심플페이)<=5.2.0
Remediation
Information
Update the WordPress 워드프레스 결제 심플페이 plugin to the latest available version (at least 5.2.2).
Event History
Jan 7, 2025
CVE Published
via MITRE·10:49 AM
Data Sourced
via MITRE·10:49 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-56281?
CVE-2024-56281 has been classified as a critical vulnerability due to its potential for remote file inclusion attacks.
2
How do I fix CVE-2024-56281?
To fix CVE-2024-56281, update CodeMShop 워드프레스 결제 심플페이 to the latest version beyond 5.2.0.
3
What systems are affected by CVE-2024-56281?
CVE-2024-56281 affects CodeMShop 워드프레스 결제 심플페이 versions 5.2.0 and earlier.
4
What type of vulnerability is CVE-2024-56281?
CVE-2024-56281 is classified as a PHP Local File Inclusion vulnerability.
5
Can CVE-2024-56281 be exploited remotely?
Yes, CVE-2024-56281 can be exploited remotely, allowing attackers to include unauthorized files on the server.