CVE-2024-37470: WordPress Woffice Core plugin <= 5.4.8 - Unauthenticated Broken Access Control vulnerability
Published Nov 1, 2024
·Updated
Missing Authorization vulnerability in WofficeIO Woffice Core allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Woffice Core: from n/a through 5.4.8.
Affected Software
3 affected components
WofficeIO Woffice Core<=5.4.8
WordPress Woffice Core<=5.4.8
Xtendify Woffice Wordpress<5.4.9
Remediation
Information
Update to 5.4.9 or a higher version.
Event History
Nov 1, 2024
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37470?
CVE-2024-37470 is classified as a high-risk vulnerability due to missing authorization controls.
2
How do I fix CVE-2024-37470?
To fix CVE-2024-37470, upgrade Woffice Core to version 5.4.9 or later to ensure proper access controls are implemented.
3
What functionality is affected by CVE-2024-37470?
CVE-2024-37470 allows unauthorized access to functionalities that are not properly constrained by Access Control Lists (ACLs).
4
Which versions of Woffice Core are affected by CVE-2024-37470?
CVE-2024-37470 affects Woffice Core versions up to and including 5.4.8.
5
Is Woffice Core the only product affected by CVE-2024-37470?
Yes, CVE-2024-37470 specifically affects the Woffice Core plugin used within the WordPress platform.