CVE-2024-33686: Broken Access Control vulnerability affecting multiple WordPress themes by Extend Themes
Missing Authorization vulnerability in Extend Themes Pathway, Extend Themes Hugo WP, Extend Themes Althea WP, Extend Themes Elevate WP, Extend Themes Brite, Extend Themes Colibri WP, Extend Themes Vertice.This issue affects Pathway: from n/a through 1.0.15; Hugo WP: from n/a through 1.0.8; Althea WP: from n/a through 1.0.13; Elevate WP: from n/a through 1.0.15; Brite: from n/a through 1.0.11; Colibri WP: from n/a through 1.0.94; Vertice: from n/a through 1.0.7.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33686?
CVE-2024-33686 is rated as a high severity vulnerability due to its potential to allow unauthorized access to sensitive areas of the affected themes.
How do I fix CVE-2024-33686?
To fix CVE-2024-33686, you should update all affected Extend Themes to their latest patched versions.
Which software is affected by CVE-2024-33686?
CVE-2024-33686 affects Extend Themes including Pathway, Hugo WP, Althea WP, Elevate WP, Brite, Colibri WP, and Vertice within specific version ranges.
What type of vulnerability is CVE-2024-33686?
CVE-2024-33686 is classified as a Missing Authorization vulnerability, which can lead to unauthorized actions within the affected themes.
Is CVE-2024-33686 easy to exploit?
Given its nature, CVE-2024-33686 can be relatively easy to exploit if the vulnerable themes are not updated or secured properly.