CVE-2024-32772: WordPress ProfileGrid plugin <= 5.7.9 - Insecure Direct Object References (IDOR) vulnerability
Published Apr 24, 2024
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9.
Affected Software
3 affected components
Metagauss Profilegrid Wordpress<5.8.0
Metagauss ProfileGrid>=n/a, <=5.7.9
WordPress ProfileGrid<=5.7.9
Remediation
Information
Update to 5.8.0 or a higher version.
Event History
Apr 24, 2024
CVE Published
via MITRE·10:19 AM
Data Sourced
via MITRE·10:19 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-32772?
CVE-2024-32772 is considered a high-severity vulnerability due to its impact on user authorization.
2
How do I fix CVE-2024-32772?
To fix CVE-2024-32772, update Metagauss ProfileGrid to version 5.8.0 or later.
3
What versions of ProfileGrid are affected by CVE-2024-32772?
CVE-2024-32772 affects Metagauss ProfileGrid versions from n/a up to 5.7.9.
4
What type of vulnerability is CVE-2024-32772?
CVE-2024-32772 is classified as an Authorization Bypass Through User-Controlled Key vulnerability.
5
In which software does CVE-2024-32772 occur?
CVE-2024-32772 occurs in the Metagauss ProfileGrid and WordPress ProfileGrid plugins.