CVE-2024-30235: WordPress Multiple Page Generator Plugin – MPG plugin <= 3.4.0 - Broken Access Control vulnerability
Published Mar 26, 2024
·Updated
Missing Authorization vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.4.0.
Affected Software
3 affected components
Themeisle Multiple Page Generator Wordpress<3.4.1
Themeisle Multiple Page Generator Plugin – MPG<=3.4.0
WordPress Multiple Page Generator Plugin – MPG<=3.4.0
Remediation
Information
Update to 3.4.1 or a higher version.
Event History
Mar 26, 2024
CVE Published
via MITRE·12:20 PM
Data Sourced
via MITRE·12:20 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-30235?
CVE-2024-30235 has a medium severity due to its missing authorization vulnerabilities in the Multiple Page Generator Plugin.
2
How do I fix CVE-2024-30235?
To fix CVE-2024-30235, upgrade the Multiple Page Generator Plugin to version 3.4.1 or later.
3
Which versions of the Multiple Page Generator Plugin are affected by CVE-2024-30235?
CVE-2024-30235 affects all versions of the Multiple Page Generator Plugin from n/a through 3.4.0.
4
What impact does CVE-2024-30235 have on users?
CVE-2024-30235 could allow unauthorized users to perform actions they should not have permission to execute.
5
Is CVE-2024-30235 a common vulnerability?
CVE-2024-30235 is a specific vulnerability found in the Multiple Page Generator Plugin, making it less common compared to more widely used plugins.