CVE-2024-33685: WordPress Startupzy theme <= 1.1.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in Jegstudio Startupzy startupzy allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Startupzy: from n/a through 1.1.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Startupzy themeto a version that resolves this vulnerability.Fixed in 1.1.2
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33685?
The severity of CVE-2024-33685 is rated as medium with a score of 4.3.
How do I fix CVE-2024-33685?
To fix CVE-2024-33685, ensure that access control settings are properly configured in the Startupzy theme.
Which versions of Startupzy are affected by CVE-2024-33685?
CVE-2024-33685 affects Jegstudio Startupzy theme versions from n/a through 1.1.1.
What kind of vulnerability is CVE-2024-33685?
CVE-2024-33685 is classified as a Broken Access Control vulnerability.
What are the potential impacts of CVE-2024-33685?
The potential impacts of CVE-2024-33685 include unauthorized access due to incorrectly configured access control security levels.