CVE-2024-37453: WordPress ProfileGrid – User Profiles, Groups and Communities plugin <= 5.8.7 - Broken Access Control vulnerability
Published Nov 1, 2024
·Updated
Missing Authorization vulnerability in ProfileGrid User Profiles ProfileGrid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfileGrid: from n/a through 5.8.7.
Affected Software
3 affected components
Metagauss Profilegrid Wordpress<5.8.8
ProfileGrid User Profiles<=5.8.7
WordPress ProfileGrid – User Profiles, Groups and Communities<=5.8.7
Remediation
Information
Update to 5.8.8 or a higher version.
Event History
Nov 1, 2024
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37453?
CVE-2024-37453 is classified as a missing authorization vulnerability that can lead to unauthorized access.
2
How do I fix CVE-2024-37453?
To fix CVE-2024-37453, upgrade ProfileGrid User Profiles to version 5.8.8 or later.
3
What versions of ProfileGrid are affected by CVE-2024-37453?
CVE-2024-37453 affects ProfileGrid versions from n/a up to 5.8.7.
4
What is the nature of the vulnerability in CVE-2024-37453?
CVE-2024-37453 involves incorrectly configured access control security levels allowing unauthorized access.
5
Who is the vendor for the affected software in CVE-2024-37453?
The vendor for the affected software in CVE-2024-37453 is Metagauss.