CVE-2024-32792: WordPress Hummingbird plugin <= 3.7.3 - Broken Access Control vulnerability
Published Jun 9, 2024
·Updated
Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affects Hummingbird: from n/a through <= 3.7.3.
Affected Software
3 affected components
WPMU DEV Hummingbird<=3.7.3
WordPress Hummingbird<=3.7.3
Incsub Hummingbird Wordpress<3.7.4
Remediation
Information
Update to 3.7.4 or a higher version.
Event History
Jun 9, 2024
CVE Published
via MITRE·12:57 PM
Data Sourced
via MITRE·12:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-32792?
The severity of CVE-2024-32792 is classified as critical due to its missing authorization vulnerability which can potentially lead to unauthorized access.
2
How do I fix CVE-2024-32792?
To fix CVE-2024-32792, upgrade your WPMU DEV Hummingbird plugin to version 3.7.4 or later.
3
Which versions of WPMU DEV Hummingbird are affected by CVE-2024-32792?
CVE-2024-32792 affects all versions of WPMU DEV Hummingbird up to and including version 3.7.3.
4
What type of vulnerability is CVE-2024-32792?
CVE-2024-32792 is a missing authorization vulnerability that can allow unauthorized actions within the application.
5
Is there a workaround for CVE-2024-32792?
There are no specific workarounds for CVE-2024-32792; the recommended action is to update to the latest version.