CVE-2024-33574: WordPress Vitepos plugin <= 3.0.1 - Broken Access Control vulnerability
Published May 8, 2024
·Updated
Missing Authorization vulnerability in appsbd Vitepos.This issue affects Vitepos: from n/a through 3.0.1.
Affected Software
1 affected component
Appsbd Vitepos (WordPress plugin)<=3.0.1
Remediation
Information
Update to 3.0.2 or a higher version.
Event History
May 8, 2024
CVE Published
via MITRE·01:35 PM
Data Sourced
via MITRE·01:35 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-33574?
CVE-2024-33574 is classified as a missing authorization vulnerability affecting the appsbd Vitepos software.
2
How do I fix CVE-2024-33574?
To fix CVE-2024-33574, update the appsbd Vitepos or WordPress Vitepos plugin to a version later than 3.0.1.
3
Which versions are affected by CVE-2024-33574?
CVE-2024-33574 affects appsbd Vitepos versions from n/a to 3.0.1, as well as the WordPress Vitepos plugin up to version 3.0.1.
4
What is the impact of CVE-2024-33574?
The impact of CVE-2024-33574 could allow unauthorized access to sensitive features or data within the affected Vitepos applications.
5
Is there a workaround for CVE-2024-33574?
A recommended workaround for CVE-2024-33574 is to restrict access to the affected application features until an update can be applied.