CVE-2024-56057

CVSS 3.1 Score 9.9 of 10 (high)

Details

Published Dec 18, 2024
CWE ID 434

Summary

CVE-2024-56057 is a newly identified vulnerability affecting the WPLMS platform from version n/a before 1.9.9.5.2. This issue involves an Unrestricted File Upload vulnerability, which permits attackers to upload a dangerous web shell to the web server using VibeThemes. The web shell, once uploaded, can be exploited to gain unauthorized access and potentially take control of the affected system. This vulnerability poses a significant security risk and should be addressed promptly by updating to the latest version of WPLMS to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share