CVE-2024-37517: WordPress Spectra plugin <= 2.13.7 - Broken Access Control vulnerability
Published Nov 1, 2024
·Updated
Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.13.7.
Affected Software
3 affected components
Brainstorm Force Spectra>=n/a, <=2.13.7
WordPress Spectra<=2.13.7
Brainstormforce Spectra Wordpress<2.13.8
Remediation
Information
Update to 2.13.8 or a higher version.
Event History
Nov 1, 2024
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37517?
The severity of CVE-2024-37517 is classified as a critical vulnerability due to improper access control configurations.
2
How do I fix CVE-2024-37517?
To fix CVE-2024-37517, update the Brainstorm Force Spectra plugin to version 2.13.8 or later.
3
Which versions of Spectra are affected by CVE-2024-37517?
CVE-2024-37517 affects all versions of Spectra from n/a up to and including 2.13.7.
4
What type of vulnerability is CVE-2024-37517?
CVE-2024-37517 is a Missing Authorization vulnerability involving incorrectly configured access control mechanisms.
5
Who is affected by CVE-2024-37517?
Users of Brainstorm Force Spectra versions 2.13.7 and below are primarily affected by CVE-2024-37517.