CVE-2024-38745: WordPress Wholesale Suite plugin <= 2.1.12 - Broken Access Control vulnerability
Published Nov 1, 2024
·Updated
Missing Authorization vulnerability in Rymera Web Co Wholesale Suite allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Wholesale Suite: from n/a through 2.1.12.
Affected Software
2 affected components
Rymera Web Co Wholesale Suite<=2.1.12
WordPress Wholesale Suite<=2.1.12
Remediation
Information
Update to 2.2.0 or a higher version.
Event History
Nov 1, 2024
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-38745?
CVE-2024-38745 is classified as a missing authorization vulnerability that allows unauthorized access to restricted functionalities.
2
How do I fix CVE-2024-38745?
To fix CVE-2024-38745, you should update the Rymera Web Co Wholesale Suite to version 2.1.13 or higher.
3
What versions are affected by CVE-2024-38745?
CVE-2024-38745 affects versions of Rymera Web Co Wholesale Suite up to and including 2.1.12.
4
What type of vulnerability is CVE-2024-38745?
CVE-2024-38745 is a broken access control vulnerability that arises from missing authorization checks.
5
Which plugin is impacted by CVE-2024-38745?
CVE-2024-38745 impacts the Wholesale Suite plugin by Rymera Web Co.