CVE-2024-32714: WordPress Academy LMS plugin <= 1.9.16 - Broken Access Control vulnerability
Published Jun 9, 2024
·Updated
Missing Authorization vulnerability in Academy LMS academy.This issue affects Academy LMS: from n/a through 1.9.16.
Affected Software
3 affected components
Academy LMS<=1.9.16
WordPress Academy LMS plugin<=1.9.16
Kodezen Academy Lms Wordpress<1.9.17
Remediation
Information
Update to 1.9.17 or a higher version.
Event History
Jun 9, 2024
CVE Published
via MITRE·05:03 PM
Data Sourced
via MITRE·05:03 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Feb 21, 57052
Event
via NVD·02:40 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-32714?
CVE-2024-32714 is classified as a missing authorization vulnerability with a moderate severity level.
2
How do I fix CVE-2024-32714?
To fix CVE-2024-32714, upgrade Academy LMS or the WordPress Academy LMS plugin to version 1.9.17 or higher.
3
Which versions of Academy LMS are affected by CVE-2024-32714?
CVE-2024-32714 affects Academy LMS versions from n/a up to and including 1.9.16.
4
Is CVE-2024-32714 specific to a particular software?
Yes, CVE-2024-32714 specifically affects the Academy LMS and the WordPress Academy LMS plugin.
5
What types of attacks can CVE-2024-32714 allow?
CVE-2024-32714 can potentially allow unauthorized users to access restricted functionalities due to missing authorization controls.