CVE-2024-31099: WordPress Phlox Core Elements plugin <= 2.15.7 - Broken Access Control vulnerability
Published Apr 1, 2024
·Updated
Missing Authorization vulnerability in Averta Shortcodes and extra features for Phlox theme auxin-elements.This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.15.7.
Affected Software
3 affected components
averta Shortcodes and extra features for Phlox theme<=2.15.7
WordPress Phlox Core Elements<=2.15.7
Averta Shortcodes And Extra Features For Phlox Theme Wordpress<2.15.8
Remediation
Information
Update to 2.15.8 or a higher version.
Event History
Apr 1, 2024
CVE Published
via MITRE·02:07 PM
Data Sourced
via MITRE·02:07 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-31099?
CVE-2024-31099 is classified as a critical severity vulnerability due to its missing authorization issues.
2
What systems are affected by CVE-2024-31099?
CVE-2024-31099 affects Averta Shortcodes and extra features for Phlox theme versions up to 2.15.7.
3
How do I fix CVE-2024-31099?
To remediate CVE-2024-31099, update the Averta Shortcodes and extra features for Phlox theme to the latest version.
4
What type of vulnerability is CVE-2024-31099?
CVE-2024-31099 is categorized as a missing authorization vulnerability.
5
Is there a known exploit for CVE-2024-31099?
As of now, specific exploit details for CVE-2024-31099 have not been publicly disclosed.