CVE-2024-37427: WordPress Timetics plugin <= 1.0.21 - Broken Access Control vulnerability
Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Timetics: from n/a through 1.0.21.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37427?
CVE-2024-37427 is classified as a missing authorization vulnerability that can lead to unauthorized access due to incorrectly configured security levels.
How do I fix CVE-2024-37427?
To fix CVE-2024-37427, ensure that proper access control measures are implemented and update to the latest version of Timetics beyond 1.0.21.
Which versions are affected by CVE-2024-37427?
CVE-2024-37427 affects Arraytics Timetics and WordPress Timetics versions up to and including 1.0.21.
What are the potential impacts of CVE-2024-37427?
The potential impacts of CVE-2024-37427 include unauthorized access to sensitive data and functionalities due to inadequate access control.
Is there a patch available for CVE-2024-37427?
Yes, a patch addressing CVE-2024-37427 is available in versions of Timetics released after 1.0.21.