First published: Tue Jun 11 2024(Updated: )
Missing Authorization vulnerability in Discourse WP Discourse.This issue affects WP Discourse: from n/a through 2.5.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Discourse | <=2.5.1 | |
WordPress WP Discourse | <=2.5.1 |
Update to 2.5.2 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-35168 is classified as a Missing Authorization vulnerability that can allow unauthorized access to restricted functionalities.
To fix CVE-2024-35168, upgrade WP Discourse to a version higher than 2.5.1 to address the missing authorization issue.
CVE-2024-35168 affects all versions of WP Discourse up to and including 2.5.1.
CVE-2024-35168 can lead to unauthorized actions being performed by attackers due to inadequate authorization checks.
While the recommended solution is updating the plugin, temporarily restricting user access might help mitigate the risk until the update is applied.