CVE-2024-37475: WordPress Newspack Newsletters plugin <= 2.13.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in Automattic Newspack Newsletters allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Newspack Newsletters: from n/a through 2.13.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37475?
CVE-2024-37475 is classified as a high severity vulnerability due to unauthorized access risks.
How do I fix CVE-2024-37475?
To fix CVE-2024-37475, upgrade the Automattic Newspack Newsletters plugin to version 2.13.3 or later immediately.
What type of vulnerability is CVE-2024-37475?
CVE-2024-37475 is a Missing Authorization vulnerability that allows access to functionality not properly constrained by Access Control Lists (ACLs).
Which versions of Newspack Newsletters are affected by CVE-2024-37475?
CVE-2024-37475 affects all versions of Newspack Newsletters up to and including version 2.13.2.
What are the potential risks associated with CVE-2024-37475?
The risks associated with CVE-2024-37475 include unauthorized access to restricted features, which may lead to data leakage or loss of integrity.