CVE-2024-34442: WordPress weDocs plugin <= 2.1.4 - Broken Access Control vulnerability
Published Jun 11, 2024
·Updated
Missing Authorization vulnerability in weDevs weDocs.This issue affects weDocs: from n/a through 2.1.4.
Affected Software
2 affected components
weDevs weDocs<=2.1.4
WordPress weDocs plugin<=2.1.4
Remediation
Information
Update to 2.1.5 or a higher version.
Event History
Jun 11, 2024
CVE Published
via MITRE·01:34 PM
Data Sourced
via MITRE·01:34 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-34442?
CVE-2024-34442 is rated as a critical severity vulnerability due to its potential for unauthorized access.
2
What impact does CVE-2024-34442 have on weDevs weDocs?
CVE-2024-34442 allows attackers to exploit missing authorization controls, potentially accessing sensitive user data.
3
How do I fix CVE-2024-34442?
To remediate CVE-2024-34442, upgrade weDocs to the latest version that addresses this vulnerability.
4
Which versions of weDevs weDocs are affected by CVE-2024-34442?
CVE-2024-34442 affects weDevs weDocs versions from its initial release up to and including 2.1.4.
5
Is CVE-2024-34442 related to WordPress?
Yes, CVE-2024-34442 also impacts the WordPress weDocs plugin version 2.1.4.