CVE-2024-35726: WordPress WooBuddy plugin <= 3.4.19 - Broken Access Control vulnerability
Published Jun 10, 2024
·Updated
Missing Authorization vulnerability in ThemeKraft WooBuddy.This issue affects WooBuddy: from n/a through 3.4.19.
Affected Software
1 affected component
Themekraft Buddypress Woocommerce My Account Integration. Create Woocommerce Member Pages Wordpress<3.4.20
Remediation
Information
Update to 3.4.20 or a higher version.
Event History
Jun 10, 2024
CVE Published
via MITRE·07:46 AM
Data Sourced
via MITRE·07:46 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-35726?
CVE-2024-35726 has a severity rating classified as a missing authorization vulnerability.
2
How do I fix CVE-2024-35726?
To fix CVE-2024-35726, update the WooBuddy plugin to version 3.4.20 or later.
3
What software is affected by CVE-2024-35726?
CVE-2024-35726 affects the ThemeKraft WooBuddy plugin versions up to and including 3.4.19.
4
What are the consequences of CVE-2024-35726?
The consequences of CVE-2024-35726 include unauthorized access to certain functionalities within the WooBuddy plugin.
5
Is there a workaround for CVE-2024-35726?
Currently, the only reliable workaround for CVE-2024-35726 is to upgrade to the patched version of the plugin.