CVE-2024-30234: WordPress WholesaleX plugin <= 1.3.1 - Broken Access Control vulnerability
Published Mar 26, 2024
·Updated
Missing Authorization vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.1.
Affected Software
3 affected components
Wholesale Team WholesaleX<=1.3.1
WordPress WholesaleX plugin<=1.3.1
wpxpo Wholesalex Wordpress<1.3.2
Remediation
Information
Update to 1.3.2 or a higher version.
Event History
Mar 26, 2024
CVE Published
via MITRE·12:16 PM
Data Sourced
via MITRE·12:16 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-30234?
CVE-2024-30234 has been categorized with a severity level that indicates a missing authorization vulnerability that could allow unauthorized access.
2
How do I fix CVE-2024-30234?
To fix CVE-2024-30234, upgrade to WholesaleX version 1.3.2 or higher, which addresses the missing authorization issue.
3
Which versions of WholesaleX are affected by CVE-2024-30234?
CVE-2024-30234 affects WholesaleX versions up to and including 1.3.1.
4
What type of vulnerability is CVE-2024-30234?
CVE-2024-30234 is classified as a missing authorization vulnerability.
5
Is the WholesaleX plugin for WordPress affected by CVE-2024-30234?
Yes, the WholesaleX plugin for WordPress versions up to and including 1.3.1 are affected by CVE-2024-30234.