What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a through <= 1.9.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a through <= 1.9.9.
Explanation of Vulnerability in Simple Terms
WPLMS versions up to 1.9.9 allow unauthenticated attackers to upload files without restriction. An attacker can upload malicious files—including PHP scripts—directly to the site, gaining the ability to run their own code on the server. This affects all users of the affected versions and requires no authentication or user interaction.
What an attacker can do
Upload and execute malicious files, including PHP code, to take control of the site.
Potential impact on your site
Complete compromise of the site; attacker can read data, modify content, install backdoors, or use the server for further attacks.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities