CVE-2024-31291: WordPress ProfileGrid plugin <= 5.7.6 - IDOR on Friend Request vulnerability
Published Apr 7, 2024
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.6.
Affected Software
3 affected components
Metagauss Profilegrid Wordpress<5.7.7
Metagauss ProfileGrid<=5.7.6
WordPress ProfileGrid<=5.7.6
Remediation
Information
Update to 5.7.7 or a higher version.
Event History
Apr 7, 2024
CVE Published
via MITRE·06:08 PM
Data Sourced
via MITRE·06:08 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-31291?
CVE-2024-31291 has been classified as a high severity vulnerability that allows authorization bypass.
2
How do I fix CVE-2024-31291?
To fix CVE-2024-31291, upgrade Metagauss ProfileGrid to version 5.7.7 or later.
3
What versions of Metagauss ProfileGrid are affected by CVE-2024-31291?
CVE-2024-31291 affects Metagauss ProfileGrid versions up to and including 5.7.6.
4
What type of vulnerability is CVE-2024-31291?
CVE-2024-31291 is an authorization bypass vulnerability that can be exploited through user-controlled keys.
5
Can CVE-2024-31291 be exploited remotely?
Yes, CVE-2024-31291 can potentially be exploited remotely by an attacker to bypass authorization controls.