CVE-2024-30522: WordPress Newsletter plugin <= 8.2.0 - IP Blacklist Bypass vulnerability
Published May 17, 2024
·Updated
Authentication Bypass by Spoofing vulnerability in Stefano Lissa & The Newsletter Team Newsletter allows Functionality Bypass.This issue affects Newsletter: from n/a through 8.2.0.
Affected Software
1 affected component
Stefano Lissa & The Newsletter Team Newsletter>n/a, <=8.2.0
Remediation
Information
Update to 8.2.1 or a higher version.
Event History
May 17, 2024
CVE Published
via MITRE·08:21 AM
Data Sourced
via MITRE·08:21 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-30522?
CVE-2024-30522 is rated as a high severity authentication bypass vulnerability.
2
How do I fix CVE-2024-30522?
To fix CVE-2024-30522, update the Newsletter plugin to version 8.2.1 or later.
3
What are the versions affected by CVE-2024-30522?
CVE-2024-30522 affects all versions of the Newsletter plugin prior to 8.2.1.
4
What does CVE-2024-30522 exploit in the Newsletter plugin?
CVE-2024-30522 exploits an authentication bypass vulnerability allowing unauthorized functionality access.
5
Is the vulnerability CVE-2024-30522 specific to a particular platform?
Yes, CVE-2024-30522 specifically affects the Newsletter plugin used in WordPress.