CVE-2024-32798: WordPress WP Travel Engine plugin <= 5.8.0 - Price Manipulation vulnerability
Published Jun 9, 2024
·Updated
Missing Authorization vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.8.0.
Affected Software
3 affected components
Wptravelengine Wp Travel Engine Wordpress<5.8.1
WP Travel Travel Engine<=5.8.0
WordPress Travel Engine<=5.8.0
Remediation
Information
Update to 5.8.1 or a higher version.
Event History
Jun 9, 2024
CVE Published
via MITRE·12:51 PM
Data Sourced
via MITRE·12:51 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-32798?
CVE-2024-32798 is classified as a missing authorization vulnerability in WP Travel Engine.
2
How do I fix CVE-2024-32798?
To fix CVE-2024-32798, update WP Travel Engine to version 5.8.1 or later.
3
Which versions of WP Travel Engine are affected by CVE-2024-32798?
CVE-2024-32798 affects WP Travel Engine versions up to 5.8.0.
4
Can the missing authorization vulnerability CVE-2024-32798 be exploited remotely?
Yes, the missing authorization vulnerability in CVE-2024-32798 can potentially be exploited remotely.
5
What impact does CVE-2024-32798 have on my website's security?
CVE-2024-32798 can lead to unauthorized access and manipulation of prices on your WP Travel Engine site.