CVE-2024-38783: WordPress Arconix FAQ plugin <= 1.9.4 - Broken Access Control vulnerability
Published Nov 1, 2024
·Updated
Missing Authorization vulnerability in Tyche Softwares Arconix FAQ allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Arconix FAQ: from n/a through 1.9.4.
Affected Software
3 affected components
tychesoftwares Arconix Faq Wordpress<1.9.5
Tyche Softwares Arconix FAQ<=1.9.4
WordPress Arconix FAQ<=1.9.4
Remediation
Information
Update to 1.9.5 or a higher version.
Event History
Nov 1, 2024
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-38783?
CVE-2024-38783 has been classified as a critical vulnerability due to its potential to allow unauthorized access to restricted functionality.
2
How do I fix CVE-2024-38783?
To fix CVE-2024-38783, update the Tyche Softwares Arconix FAQ plugin to version 1.9.5 or later.
3
What functionality is affected by CVE-2024-38783?
CVE-2024-38783 affects the Access Control Lists (ACLs) which improperly constrain functionality in the Arconix FAQ plugin.
4
Who is affected by CVE-2024-38783?
All users of Tyche Softwares Arconix FAQ versions from n/a through 1.9.4 are affected by CVE-2024-38783.
5
What type of vulnerability is CVE-2024-38783?
CVE-2024-38783 is categorized as a Missing Authorization vulnerability.