CVE-2024-32683: WordPress WP Ultimate Review plugin <= 2.2.5 - Insecure Direct Object References (IDOR) vulnerability
Published Apr 19, 2024
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through 2.2.5.
Affected Software
3 affected components
Wpmet WP Ultimate Review<=2.2.5
WordPress WP Ultimate Review<=2.2.5
Wpmet Wp Ultimate Review Wordpress<2.3.0
Remediation
Information
Update to 2.3.0 or a higher version.
Event History
Apr 19, 2024
CVE Published
via MITRE·11:57 AM
Data Sourced
via MITRE·11:57 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-32683?
CVE-2024-32683 has been classified as a significant risk due to its potential for authorization bypass.
2
How do I fix CVE-2024-32683?
To fix CVE-2024-32683, update WP Ultimate Review to the latest version or apply any available patches.
3
What versions are affected by CVE-2024-32683?
CVE-2024-32683 affects WP Ultimate Review versions up to and including 2.2.5.
4
What type of vulnerability is CVE-2024-32683?
CVE-2024-32683 is an authorization bypass vulnerability that can be exploited through user-controlled keys.
5
Can CVE-2024-32683 be exploited remotely?
Yes, CVE-2024-32683 can potentially be exploited remotely if an attacker has access to the affected WordPress setup.