CVE-2024-2906: WordPress Radio Player plugin <= 2.0.73 - Unauthenticated Broken Access Control vulnerability
Missing Authorization vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2906?
CVE-2024-2906 is classified as a Missing Authorization vulnerability which can lead to unauthorized access to features or data.
How do I fix CVE-2024-2906?
To mitigate CVE-2024-2906, update the SoftLab Radio Player to version 2.0.74 or later that addresses the vulnerability.
Which software versions are affected by CVE-2024-2906?
CVE-2024-2906 affects SoftLab Radio Player versions up to and including 2.0.73 and the WordPress Radio Player plugin version up to and including 2.0.73.
What types of attacks can exploit CVE-2024-2906?
Exploitation of CVE-2024-2906 can allow unauthorized users to access and manipulate functionalities intended for authenticated users.
Who is the vendor for the affected software in CVE-2024-2906?
The vendor for the affected software in CVE-2024-2906 is SoftLab for the Radio Player and WordPress for the Radio Player plugin.