CVE-2024-31290: WordPress Demo My WordPress plugin <= 1.0.9.1 - Unauthenticated Privilege Escalation vulnerability
Published May 17, 2024
·Updated
Improper Privilege Management vulnerability in CodeRevolution Demo My WordPress allows Privilege Escalation.This issue affects Demo My WordPress: from n/a through 1.0.9.1.
Affected Software
2 affected components
CodeRevolution Demo My WordPress<=1.0.9.1
WordPress Demo My WordPress<=1.0.9.1
Remediation
Information
Update to 1.1.0 or a higher version.
Event History
May 17, 2024
CVE Published
via MITRE·08:54 AM
Data Sourced
via MITRE·08:54 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-31290?
CVE-2024-31290 is classified as a privilege escalation vulnerability.
2
How do I fix CVE-2024-31290?
To fix CVE-2024-31290, users should update the CodeRevolution Demo My WordPress plugin to the latest version beyond 1.0.9.1.
3
Which versions of CodeRevolution Demo My WordPress are affected by CVE-2024-31290?
CVE-2024-31290 affects CodeRevolution Demo My WordPress from n/a through version 1.0.9.1.
4
Can unprivileged users exploit CVE-2024-31290?
Yes, CVE-2024-31290 allows unprivileged users to escalate their privileges within the application.
5
Is CVE-2024-31290 specific to any particular software?
Yes, CVE-2024-31290 specifically affects the CodeRevolution Demo My WordPress plugin.