CVE-2024-30465: WordPress PageLayer plugin <= 1.8.1 - Broken Access Control vulnerability
Published Jun 9, 2024
·Updated
Missing Authorization vulnerability in Pagelayer Team PageLayer.This issue affects PageLayer: from n/a through 1.8.1.
Affected Software
1 affected component
PageLayer Pagelayer WordPress<1.8.2
Remediation
Information
Update to 1.8.2 or a higher version.
Event History
Jun 9, 2024
CVE Published
via MITRE·10:42 AM
Data Sourced
via MITRE·10:42 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-30465?
CVE-2024-30465 is classified as a medium severity vulnerability due to missing authorization mechanisms.
2
How do I fix CVE-2024-30465?
To fix CVE-2024-30465, update the Pagelayer plugin to version 1.8.2 or newer.
3
Which versions of Pagelayer are affected by CVE-2024-30465?
CVE-2024-30465 affects Pagelayer versions from n/a through 1.8.1.
4
What type of vulnerability is CVE-2024-30465?
CVE-2024-30465 is a missing authorization vulnerability.
5
Can CVE-2024-30465 be exploited remotely?
Yes, CVE-2024-30465 can be exploited remotely due to the nature of the missing authorization issue.