CVE-2024-38707: WordPress EmbedPress plugin <= 4.0.4 - Broken Access Control vulnerability
Missing Authorization vulnerability in WPDeveloper EmbedPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EmbedPress: from n/a through 4.0.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38707?
CVE-2024-38707 has been classified as a critical vulnerability due to its potential to exploit incorrectly configured access controls.
How do I fix CVE-2024-38707?
To fix CVE-2024-38707, update the WPDeveloper EmbedPress plugin to the latest version that addresses the authorization issues.
What versions of EmbedPress are affected by CVE-2024-38707?
CVE-2024-38707 affects WPDeveloper EmbedPress versions from n/a up to and including 4.0.4.
What kind of attack can CVE-2024-38707 enable?
CVE-2024-38707 allows attackers to gain unauthorized access due to missing authorization checks.
Who is affected by CVE-2024-38707?
Users of the EmbedPress plugin for WordPress, specifically those using versions up to 4.0.4, are affected by CVE-2024-38707.