CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-56045

CVSS 9.3v3.1pub. 2024-12-31upd. 2026-04-23

Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.

🤖 AI Analysis
How it works

The vulnerability consists of improper sanitization of file paths — an attacker can provide a crafted string in the format '.../...//' (a technique to bypass simple filters blocking '../'), which after processing by the application leads to the specified directory outside the main plugin directory. This mechanism allows operations outside the permitted area of the server's file system. The attack is possible without any authentication and is performed remotely over the network.

Impact

An attacker can delete any directories accessible in the context of the web server's permissions, which may lead to service unavailability (DoS), damage to the WordPress installation, or destruction of application data. It is also possible to compromise the integrity of the server's file system.

Mitigation & patch

The WPLMS plugin must be updated immediately to version 1.9.9.5 or newer. Patch details are available in the Patchstack database and in the WordPress plugin repository.

Who is affected

WPLMS plugin (wplms_plugin) by VibeThemes for WordPress — versions from unspecified (n/a) to versions below 1.9.9.5.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H
  • Vibethemes WordPress Learning Management System

    APP
    Vibethemes
    < 1.9.9.5
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2024-56046CRITICAL10.0PL ✓same product

Niekontrolowane przesyłanie plików w pluginie WPLMS — upload Web Shell

CVE-2024-56042CRITICAL9.3PL ✓same product

SQL Injection w pluginie WPLMS dla WordPress (VibeThemes)

CVE-2024-56043CRITICAL9.8PL ✓same product

WPLMS Plugin – nieuwierzytelniona eskalacja uprawnień (privilege escalation)

CVE-2024-56044CRITICAL9.8PL ✓same product

Authentication Bypass w pluginie WPLMS dla WordPress (do wersji 1.9.9)

CVE-2024-56050CRITICAL9.9PL ✓same product

Nieograniczony upload plików w WPLMS — możliwość wgrania Web Shell