CVE-2024-30470: WordPress YITH WooCommerce Account Funds Premium plugin <= 1.32.0 - Broken Access Control vulnerability
Missing Authorization vulnerability in YITH YITH WooCommerce Account Funds Premium.This issue affects YITH WooCommerce Account Funds Premium: from n/a through 1.33.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30470?
CVE-2024-30470 is classified as a critical vulnerability due to its potential for unauthorized access to account funds.
How do I fix CVE-2024-30470?
To fix CVE-2024-30470, update the YITH WooCommerce Account Funds Premium plugin to version 1.34.0 or later.
What systems are affected by CVE-2024-30470?
CVE-2024-30470 affects YITH WooCommerce Account Funds Premium versions from n/a through 1.33.0.
What is the nature of the vulnerability in CVE-2024-30470?
CVE-2024-30470 is a Missing Authorization vulnerability that allows unauthorized actions related to account funds.
What should users do if they are unable to update due to compatibility issues with CVE-2024-30470?
If updating is not possible due to compatibility issues, users should consider disabling the YITH WooCommerce Account Funds Premium plugin until a fix can be applied.