CVE-2024-37254: WordPress WP File Manager plugin <= 7.2.7 - Broken Access Control vulnerability
Missing Authorization vulnerability in mndpsingh287 File Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects File Manager: from n/a through 7.2.7.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37254?
CVE-2024-37254 is classified as a Missing Authorization vulnerability that allows unauthorized access due to incorrect access control configurations.
How do I fix CVE-2024-37254?
To fix CVE-2024-37254, upgrade to a version of mndpsingh287 File Manager or WordPress WP File Manager that is beyond 7.2.7.
Who is affected by CVE-2024-37254?
CVE-2024-37254 affects users of mndpsingh287 File Manager and WordPress WP File Manager versions up to and including 7.2.7.
What type of vulnerability is CVE-2024-37254?
CVE-2024-37254 is a Missing Authorization vulnerability that compromises access control.
Can CVE-2024-37254 be exploited easily?
Yes, CVE-2024-37254 can be easily exploited due to the absence of proper authorization checks.