← Back to browse · API

CVE-2024-10470

Severity
CRITICAL
CVSS
9.8
EPSS
0.33856
Risk score
51.05
CISA KEV
No
PoC
No
Published
2024-11-09
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2024-33144, GHSA-PQM3-X6XP-M28Q
Products
vibethemes:WPLMS Learning Management System for WordPress, WordPress LMS 0 ≤4.962
Sources
euvd EUVD-2024-33144

Description

The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in all versions up to, and including, 4.962. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The theme is vulnerable even when it is not activated.

References