CVE-2024-6459: News Element Elementor Blog Magazine < 1.0.6 - Unauthenticated LFI
The News Element Elementor Blog Magazine WordPress plugin before 1.0.6 is vulnerable to Local File Inclusion via the template parameter. This makes it possible for unauthenticated attacker to include and execute PHP files on the server, allowing the execution of any PHP code in those files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6459?
CVE-2024-6459 has a medium severity rating due to its potential to allow unauthorized access and execution of PHP code.
How do I fix CVE-2024-6459?
To fix CVE-2024-6459, upgrade the News Element Elementor Blog Magazine plugin to version 1.0.6 or later immediately.
Who is affected by CVE-2024-6459?
Users of the News Element Elementor Blog Magazine WordPress plugin prior to version 1.0.6 are affected by CVE-2024-6459.
What type of attack does CVE-2024-6459 facilitate?
CVE-2024-6459 facilitates local file inclusion attacks, allowing attackers to execute arbitrary PHP files on the server.
Can CVE-2024-6459 be exploited without authentication?
Yes, CVE-2024-6459 can be exploited by unauthenticated attackers, making it particularly dangerous.