CVE-2024-30485: WordPress Finale Lite plugin <= 2.18.0 - Subscriber+ Arbitrary Plugin Installation/Activation vulnerability
Missing Authorization vulnerability in XLPlugins Finale Lite.This issue affects Finale Lite: from n/a through 2.18.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30485?
CVE-2024-30485 is considered a missing authorization vulnerability that can allow unauthorized access to certain functions in the affected software.
How do I fix CVE-2024-30485?
To fix CVE-2024-30485, update XLPlugins Finale Lite to version 2.18.1 or later, which addresses this vulnerability.
Which versions of Finale Lite are affected by CVE-2024-30485?
CVE-2024-30485 affects XLPlugins Finale Lite versions from n/a up to 2.18.0.
What are the potential risks of CVE-2024-30485?
The risks associated with CVE-2024-30485 include unauthorized manipulation of the Finale Lite settings and possible installation of plugins without appropriate permissions.
Is there a workaround for CVE-2024-30485?
There are no officially recommended workarounds for CVE-2024-30485; updating to the latest version is the best course of action.