CVE-2024-37505: WordPress Business One Page theme <= 1.2.9 - Broken Access Control on Notice Dismissal vulnerability
Missing Authorization vulnerability in Rara Themes Business One Page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Business One Page: from n/a through 1.2.9.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37505?
CVE-2024-37505 has a high severity rating due to the missing authorization vulnerability that can lead to unauthorized access.
How do I fix CVE-2024-37505?
To fix CVE-2024-37505, update the Rara Themes Business One Page to version 1.3.0 or later.
Which versions of Rara Themes Business One Page are affected by CVE-2024-37505?
CVE-2024-37505 affects all versions of Rara Themes Business One Page up to and including version 1.2.9.
What types of attacks can exploit CVE-2024-37505?
CVE-2024-37505 can be exploited to gain unauthorized access to restricted areas of the application due to misconfigured access controls.
Is CVE-2024-37505 specific to any platform?
Yes, CVE-2024-37505 specifically affects the WordPress theme known as Business One Page provided by Rara Themes.