CVE-2024-37456: WordPress Simple Newsletter Plugin – Noptin plugin <= 3.4.2 - Broken Access Control vulnerability
Published Nov 1, 2024
·Updated
Missing Authorization vulnerability in Noptin Newsletter Noptin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Noptin: from n/a through 3.4.2.
Affected Software
2 affected components
Noptin Noptin<=3.4.2
Noptin Simple Newsletter Plugin<=3.4.2
Remediation
Information
Update to 3.4.3 or a higher version.
Event History
Nov 1, 2024
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-37456?
CVE-2024-37456 has been classified as a critical severity vulnerability due to missing authorization checks in the Noptin Newsletter plugin.
2
How do I fix CVE-2024-37456?
To resolve CVE-2024-37456, update the Noptin Newsletter plugin to version 3.4.3 or later where this vulnerability has been addressed.
3
What version of Noptin is affected by CVE-2024-37456?
CVE-2024-37456 affects Noptin versions up to and including 3.4.2.
4
What functionality is compromised by CVE-2024-37456?
CVE-2024-37456 allows unauthorized access to functionality not properly constrained by Access Control Lists (ACLs).
5
Is the Simple Newsletter Plugin also affected by CVE-2024-37456?
Yes, the Simple Newsletter Plugin versions up to 3.4.2 are also affected by CVE-2024-37456.