CVE-2024-34822: WordPress weMail plugin <= 1.14.2 - Broken Access Control vulnerability
Published Jun 11, 2024
·Updated
Missing Authorization vulnerability in weDevs weMail.This issue affects weMail: from n/a through 1.14.2.
Affected Software
1 affected component
weDevs Wemail Wordpress<1.14.3
Remediation
Information
Update to 1.14.3 or a higher version.
Event History
Jun 11, 2024
CVE Published
via MITRE·03:26 PM
Data Sourced
via MITRE·03:26 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-34822?
CVE-2024-34822 is classified as a moderate severity vulnerability due to its potential for unauthorized access.
2
How do I fix CVE-2024-34822?
To remediate CVE-2024-34822, upgrade weMail to version 1.14.3 or later.
3
What specific feature is affected by CVE-2024-34822?
CVE-2024-34822 affects the authorization controls within weMail, allowing unauthorized actions.
4
Can CVE-2024-34822 be exploited remotely?
Yes, CVE-2024-34822 can potentially be exploited remotely due to its inadequate authorization checks.
5
Is CVE-2024-34822 related to any specific version of weMail?
CVE-2024-34822 impacts weMail versions from n/a to 1.14.2.