WPLMS Learning Management System for WordPress <= 4.962 - Unauthenticated Arbitrary File Read and Deletion
60Vexday Risk Score
Acompanhe. Ela tem prova de conceito pública.
ssvc Attendcvss 9.8epss 34%
da publicação à arma0 dias
Publicada no NVD9 de nov.
1ª PoC8 de nov.
probabilidade de exploração
34%top 2% das CVEs
exploração observada
nãonenhuma fonte reporta
2 exploit(s) público(s)
The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in all versions up to, and including, 4.962. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The theme is vulnerable even when it is not activated.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
PoCs públicas encontradas — 2
githubgithub.com/RandomRobbieBF/CVE-2024-10470★ 0githubgithub.com/0xshoriful/CVE-2024-10470★ 0⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.