BMLT Meeting Map
cpe:2.3:a:bmlt:meeting_map:*:*:*:*:wordpress:*:*
- <= 2.6.0
A local file inclusion vulnerability has been identified in the BMLT Meeting Map plugin for WordPress, affecting all versions through 2.6.0. The vulnerability arises in the 'bmlt_meeting_map' shortcode, allowing authenticated attackers with Contributor-level access and above to include and execute arbitrary files on the server. This exploitation could bypass access controls, access sensitive data, or execute PHP code from included files, particularly if the site allows uploading of images or other 'safe' file types.
Exploitation of this vulnerability could lead to unauthorized file inclusion and execution of PHP code on the server, potentially allowing attackers to bypass access controls, access sensitive information, or execute malicious code.
To reproduce this vulnerability, an authenticated user with Contributor-level access or higher can use the 'bmlt_meeting_map' shortcode on a WordPress page. This will trigger the local file inclusion vulnerability, allowing the execution of arbitrary PHP files on the server.
Users are advised to update the BMLT Meeting Map plugin to version 2.6.1 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.