CVE-2024-31352: WordPress Icegram Express plugin <= 5.7.13 - Broken Access Control vulnerability
Published Jun 9, 2024
·Updated
Missing Authorization vulnerability in Email Subscribers & Newsletters.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.13.
Affected Software
1 affected component
Icegram Email Subscribers \& Newsletters Wordpress<5.7.14
Remediation
Information
Update to 5.7.14 or a higher version.
Event History
Jun 9, 2024
CVE Published
via MITRE·05:23 PM
Data Sourced
via MITRE·05:23 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-31352?
The severity of CVE-2024-31352 is categorized as medium due to its missing authorization issue.
2
How do I fix CVE-2024-31352?
To fix CVE-2024-31352, update the Email Subscribers & Newsletters plugin to version 5.7.14 or later.
3
What versions are affected by CVE-2024-31352?
CVE-2024-31352 affects Email Subscribers & Newsletters plugin versions up to 5.7.13.
4
What type of vulnerability is CVE-2024-31352?
CVE-2024-31352 is a Missing Authorization vulnerability.
5
Is CVE-2024-31352 exploited in the wild?
As of now, there is no indication that CVE-2024-31352 is actively being exploited in the wild.