CVE-2024-31366: WordPress Post Type Builder (PTB) plugin <= 2.0.8 - Auth. Arbitrary Post/Page Creation vulnerability
Published Apr 9, 2024
·Updated
Missing Authorization vulnerability in Themify Post Type Builder (PTB).This issue affects Post Type Builder (PTB): from n/a through 2.0.8.
Affected Software
1 affected component
Themify Post Type Builder (PTB)<=2.0.8
Event History
Apr 9, 2024
CVE Published
via MITRE·07:22 AM
Data Sourced
via MITRE·07:22 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-31366?
CVE-2024-31366 is classified as a missing authorization vulnerability that can lead to unauthorized capabilities within the Themify Post Type Builder.
2
How do I fix CVE-2024-31366?
To fix CVE-2024-31366, you should update the Themify Post Type Builder plugin to version 2.0.9 or later.
3
What is affected by CVE-2024-31366?
CVE-2024-31366 affects all versions of Themify Post Type Builder from release up to and including 2.0.8.
4
Who is the vendor responsible for CVE-2024-31366?
The vendor responsible for CVE-2024-31366 is Themify, which provides the Post Type Builder plugin.
5
What implications does CVE-2024-31366 have for users?
Users impacted by CVE-2024-31366 may experience unauthorized access to create posts or pages, potentially compromising website security.