First published: Tue Aug 13 2024(Updated: )
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Codection Import and export users and customers allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Import and export users and customers: from n/a through 1.26.8.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Import and Export Users and Customers | <=1.26.8 | |
WordPress Import and Export Users and Customers | <=1.26.8 |
Update to 1.26.9 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-38787 is classified as a moderate severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2024-38787, update the Codection Import and Export Users and Customers plugin to version 1.26.9 or later.
CVE-2024-38787 involves the exposure of sensitive information to unauthorized actors due to improperly constrained access control lists (ACLs).
CVE-2024-38787 affects versions of Codection Import and Export Users and Customers from n/a up to and including 1.26.8.
Yes, CVE-2024-38787 is specific to the Codection Import and Export Users and Customers plugin used in WordPress.