CVE-2024-25917: WordPress WP Setup Wizard plugin <= 1.0.8.1 - Auth. Full Database Download Vulnerability
Published Apr 25, 2024
·Updated
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodeRevolution WP Setup Wizard.This issue affects WP Setup Wizard: from n/a through 1.0.8.1.
Affected Software
1 affected component
CodeRevolution WP Setup Wizard<=1.0.8.1
Remediation
Information
Update to 1.0.8.2 or a higher version.
Event History
Apr 25, 2024
CVE Published
via MITRE·08:39 AM
Data Sourced
via MITRE·08:39 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-25917?
The severity of CVE-2024-25917 is classified as a medium risk due to unauthorized access to sensitive information.
2
How do I fix CVE-2024-25917?
To fix CVE-2024-25917, update the CodeRevolution WP Setup Wizard plugin to version 1.0.8.2 or later.
3
What versions are affected by CVE-2024-25917?
CVE-2024-25917 affects versions of CodeRevolution WP Setup Wizard up to and including 1.0.8.1.
4
What type of vulnerability is CVE-2024-25917?
CVE-2024-25917 is an exposure of sensitive information to an unauthorized actor vulnerability.
5
Who is impacted by CVE-2024-25917?
Users of the CodeRevolution WP Setup Wizard plugin, specifically those running versions up to 1.0.8.1, are impacted by CVE-2024-25917.