CVE-2024-37425: WordPress Newspack Blocks plugin <= 3.0.8 - Broken Access Control vulnerability
Missing Authorization vulnerability in Automattic Newspack Blocks newspack-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Newspack Blocks: from n/a through 3.0.8.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37425?
CVE-2024-37425 is classified as a missing authorization vulnerability that could lead to unauthorized access due to incorrectly configured access controls.
How do I fix CVE-2024-37425?
To fix CVE-2024-37425, update the Automattic Newspack Blocks plugin to version 3.0.9 or later to ensure proper access control.
Which versions are affected by CVE-2024-37425?
CVE-2024-37425 affects the Automattic Newspack Blocks plugin versions from n/a up to and including 3.0.8.
What are the potential risks of CVE-2024-37425?
The risks of CVE-2024-37425 include potential unauthorized data access, manipulation, or exposure due to inadequate authorization checks.
Who is primarily affected by CVE-2024-37425?
Users of the Automattic Newspack Blocks plugin, particularly those using versions up to 3.0.8, are primarily affected by CVE-2024-37425.