CVE-2024-30513: WordPress ProfileGrid plugin <= 5.7.2 - Insecure Direct Object References (IDOR) vulnerability
Published Mar 29, 2024
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.2.
Affected Software
3 affected components
Metagauss Profilegrid Wordpress<5.7.3
Metagauss ProfileGrid<=5.7.2
WordPress ProfileGrid Plugin<=5.7.2
Remediation
Information
Update to 5.7.3 or a higher version.
Event History
Mar 29, 2024
CVE Published
via MITRE·03:50 PM
Data Sourced
via MITRE·03:50 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-30513?
CVE-2024-30513 is considered a high severity vulnerability due to its potential for unauthorized access.
2
How do I fix CVE-2024-30513?
To fix CVE-2024-30513, update the Metagauss ProfileGrid plugin to version 5.7.3 or later.
3
What versions are affected by CVE-2024-30513?
CVE-2024-30513 affects Metagauss ProfileGrid versions from n/a up to 5.7.2.
4
What type of vulnerability is CVE-2024-30513?
CVE-2024-30513 is an authorization bypass through user-controlled key vulnerability.
5
Who is affected by CVE-2024-30513?
Users of the Metagauss ProfileGrid plugin for WordPress who are on versions 5.7.2 or lower are impacted by CVE-2024-30513.