First published: Tue Jun 11 2024(Updated: )
Missing Authorization vulnerability in Wpmet WP Fundraising Donation and Crowdfunding Platform.This issue affects WP Fundraising Donation and Crowdfunding Platform: from n/a through 1.6.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP Fundraising Donation and Crowdfunding Platform | <=1.6.4 | |
WordPress FundEngine | <=1.6.4 |
Update to 1.7.0 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-34758 is classified as a medium security risk due to the missing authorization vulnerability.
To fix CVE-2024-34758, update the WP Fundraising Donation and Crowdfunding Platform plugin to version 1.6.5 or later.
CVE-2024-34758 affects versions up to and including 1.6.4 of the WP Fundraising Donation and Crowdfunding Platform.
The missing authorization vulnerability in CVE-2024-34758 could allow unauthorized users to access sensitive functionalities.
The vendor for CVE-2024-34758 is Wpmet.