CVE-2023-47224: WordPress WP Travel plugin <= 7.8.0 - Broken Access Control vulnerability
Published Jan 2, 2025
·Updated
Missing Authorization vulnerability in WP Travel WP Travel wp-travel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Travel: from n/a through <= 7.8.0.
Affected Software
1 affected component
WP Travel WP Travel<=7.8.0
Remediation
Information
No patched version is available.
Event History
Jan 2, 2025
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-47224?
CVE-2023-47224 is classified as a serious security vulnerability due to its potential for unauthorized access.
2
How do I fix CVE-2023-47224?
To fix CVE-2023-47224, update WP Travel to the latest version beyond 7.8.0 to ensure proper access control configurations.
3
What type of vulnerability is CVE-2023-47224?
CVE-2023-47224 is a Missing Authorization vulnerability that affects the access control mechanisms in WP Travel.
4
What versions of WP Travel are affected by CVE-2023-47224?
CVE-2023-47224 affects all versions of WP Travel from n/a up to and including 7.8.0.
5
Who is affected by CVE-2023-47224?
Users of WP Travel who have not updated to the latest version are at risk due to CVE-2023-47224.