CVE-2024-22298: WordPress Amelia plugin <= 1.0.98 - Broken Access Control vulnerability
Published Jun 10, 2024
·Updated
Missing Authorization vulnerability in TMS Amelia ameliabooking.This issue affects Amelia: from n/a through 1.0.98.
Affected Software
3 affected components
TMS Amelia<=1.0.98
WordPress Amelia plugin<=1.0.98
Tms-outsource Amelia Wordpress<1.0.99
Remediation
Information
Update to 1.0.99 or a higher version.
Event History
Jun 10, 2024
CVE Published
via MITRE·08:06 AM
Data Sourced
via MITRE·08:06 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-22298?
The severity of CVE-2024-22298 is assessed as critical due to the missing authorization vulnerability that can lead to unauthorized access.
2
How do I fix CVE-2024-22298?
To fix CVE-2024-22298, update the TMS Amelia plugin to the latest version available, which addresses the missing authorization issue.
3
Which versions of TMS Amelia are affected by CVE-2024-22298?
CVE-2024-22298 affects all versions of TMS Amelia from n/a up to and including version 1.0.98.
4
What type of vulnerability is CVE-2024-22298?
CVE-2024-22298 is classified as a Missing Authorization vulnerability, posing a risk for access control breaches.
5
Can CVE-2024-22298 affect WordPress installations?
Yes, CVE-2024-22298 can affect WordPress installations using the Amelia plugin up to version 1.0.98.