CVE-2024-34758: WordPress FundEngine – Donation and Crowdfunding Platform plugin <= 1.6.4 - Broken Access Control vulnerability
Published Jun 11, 2024
·Updated
Missing Authorization vulnerability in Wpmet WP Fundraising Donation and Crowdfunding Platform.This issue affects WP Fundraising Donation and Crowdfunding Platform: from n/a through 1.6.4.
Affected Software
2 affected components
Wpmet WP Fundraising Donation and Crowdfunding Platform<=1.6.4
WordPress FundEngine – Donation and Crowdfunding Platform<=1.6.4
Remediation
Information
Update to 1.7.0 or a higher version.
Event History
Jun 11, 2024
CVE Published
via MITRE·04:13 PM
Data Sourced
via MITRE·04:13 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-34758?
The severity of CVE-2024-34758 is classified as a medium security risk due to the missing authorization vulnerability.
2
How do I fix CVE-2024-34758?
To fix CVE-2024-34758, update the WP Fundraising Donation and Crowdfunding Platform plugin to version 1.6.5 or later.
3
What versions of WP Fundraising Donation and Crowdfunding Platform are affected by CVE-2024-34758?
CVE-2024-34758 affects versions up to and including 1.6.4 of the WP Fundraising Donation and Crowdfunding Platform.
4
What are the potential impacts of CVE-2024-34758?
The missing authorization vulnerability in CVE-2024-34758 could allow unauthorized users to access sensitive functionalities.
5
Who is the vendor for CVE-2024-34758?
The vendor for CVE-2024-34758 is Wpmet.