CVE-2024-34389: WordPress WP Post Author plugin <= 3.6.4 - Broken Access Control vulnerability
Published May 6, 2024
·Updated
Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4.
Affected Software
2 affected components
Afthemes Wp Post Author Wordpress<3.7.5
WordPress WP Post Author<=3.6.4
Event History
May 6, 2024
CVE Published
via MITRE·06:42 PM
Data Sourced
via MITRE·06:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-34389?
CVE-2024-34389 is a critical vulnerability due to missing authorization in WP Post Author.
2
How do I fix CVE-2024-34389?
To fix CVE-2024-34389, update the WP Post Author plugin to the latest version beyond 3.6.4.
3
What software versions are affected by CVE-2024-34389?
CVE-2024-34389 affects all versions of WP Post Author up to and including 3.6.4.
4
What type of vulnerability is CVE-2024-34389?
CVE-2024-34389 is classified as a missing authorization vulnerability.
5
Is there a workaround for CVE-2024-34389 if I can't update?
No specific workaround is recommended for CVE-2024-34389; updating is the best approach to mitigate the risk.