The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in all versions up to, and including, 4.962. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The theme is vulnerable even when it is not activated.
History

Tue, 12 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Vibethemes
Vibethemes wordpress Learning Management System
CPEs cpe:2.3:a:vibethemes:wordpress_learning_management_system_:*:*:*:*:*:wordpress:*:*
Vendors & Products Vibethemes
Vibethemes wordpress Learning Management System
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 09 Nov 2024 05:45:00 +0000

Type Values Removed Values Added
Description The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in all versions up to, and including, 4.962. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The theme is vulnerable even when it is not activated.
Title WPLMS Learning Management System for WordPress <= 4.962 - Unauthenticated Arbitrary File Read and Deletion
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-11-09T05:40:22.357Z

Updated: 2024-11-12T18:41:47.848Z

Reserved: 2024-10-28T15:48:33.963Z

Link: CVE-2024-10470

cve-icon Vulnrichment

Updated: 2024-11-12T18:41:41.469Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-09T06:15:15.967

Modified: 2024-11-12T13:56:24.513

Link: CVE-2024-10470

cve-icon Redhat

No data.