CVE-2024-34387: WordPress WP Post Author plugin <= 3.6.4 - Rating Value Manipulation vulnerability
Published May 6, 2024
·Updated
Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4.
Affected Software
2 affected components
AF themes WP Post Author<=3.6.4
Afthemes Wp Post Author Wordpress<3.6.5
Event History
May 6, 2024
CVE Published
via MITRE·06:49 PM
Data Sourced
via MITRE·06:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-34387?
CVE-2024-34387 has been classified as a missing authorization vulnerability that can affect the security of WordPress sites using the WP Post Author plugin.
2
How do I fix CVE-2024-34387?
To fix CVE-2024-34387, it is recommended to upgrade the WP Post Author plugin to version 3.6.5 or later.
3
Which versions are affected by CVE-2024-34387?
CVE-2024-34387 affects versions of the WP Post Author plugin from n/a through 3.6.4.
4
What type of vulnerability is CVE-2024-34387?
CVE-2024-34387 is categorized as a missing authorization vulnerability that could allow unauthorized actions.
5
Who is the vendor of CVE-2024-34387?
The vendor of the affected software related to CVE-2024-34387 is AF themes.