CVE-2024-30542: WordPress WholesaleX plugin <= 1.3.2 - Unauthenticated Privilege Escalation vulnerability
Published May 17, 2024
·Updated
Improper Privilege Management vulnerability in Wholesale WholesaleX allows Privilege Escalation.This issue affects WholesaleX: from n/a through 1.3.2.
Affected Software
3 affected components
wpxpo Wholesalex Wordpress<1.3.3
Wholesale WholesaleX<=1.3.2
WordPress WholesaleX plugin<=1.3.2
Remediation
Information
Update to 1.3.3 or a higher version.
Event History
May 17, 2024
CVE Published
via MITRE·08:52 AM
Data Sourced
via MITRE·08:52 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-30542?
CVE-2024-30542 has a medium severity level, indicating a significant risk of privilege escalation.
2
How do I fix CVE-2024-30542?
To fix CVE-2024-30542, upgrade WholesaleX to version 1.3.3 or later.
3
What versions of WholesaleX are affected by CVE-2024-30542?
CVE-2024-30542 affects WholesaleX versions up to and including 1.3.2.
4
Is CVE-2024-30542 a remote vulnerability?
CVE-2024-30542 allows unauthenticated users to escalate privileges, making it a remote vulnerability.
5
Who is impacted by CVE-2024-30542?
Users of WholesaleX versions 1.3.2 or earlier are impacted by CVE-2024-30542.