CVE-2024-56281

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 7, 2025
CWE ID 98

Summary

CVE-2024-56281 is a newly disclosed vulnerability affecting the CodeMShop WordPress plugin for payment processing. The issue involves improper control of filename for include/require statements, leading to a Local File Inclusion (LFI) vulnerability. This flaw enables an attacker to potentially gain unauthorized access to sensitive data or execute arbitrary code on affected installations of the plugin, ranging from version n/a through 5.2.0. To mitigate this risk, it's crucial for users to update to a patched version as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share