CVE-2024-37506: WordPress Donation Forms by Charitable plugin <= 1.8.1.7 - Broken Access Control vulnerability
Missing Authorization vulnerability in Charitable Donations & Fundraising Team Charitable allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Charitable: from n/a through 1.8.1.7.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37506?
CVE-2024-37506 is classified as a critical vulnerability due to missing authorization controls that allow unauthorized access to sensitive functionalities.
How do I fix CVE-2024-37506?
To fix CVE-2024-37506, update Charitable to version 1.8.1.8 or later to ensure proper access control is enforced.
What systems are affected by CVE-2024-37506?
CVE-2024-37506 affects Charitable versions up to and including 1.8.1.7 and WordPress Donation Forms by Charitable with the same version range.
What are the consequences of CVE-2024-37506?
If exploited, CVE-2024-37506 can lead to unauthorized access to functions and operations that should be restricted, compromising user data and application integrity.
Is there any workaround for CVE-2024-37506?
Currently, the best practice for mitigating CVE-2024-37506 is to upgrade to a patched version, as there are no reliable workarounds available.