CVE-2024-39625: WordPress Icegram Engage plugin <= 3.1.24 - Unauthenticated Message Duplication Vulnerability
Published Nov 1, 2024
·Updated
Missing Authorization vulnerability in icegram Icegram allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Icegram: from n/a through 3.1.24.
Affected Software
2 affected components
Icegram Icegram>n/a, <=3.1.24
WordPress Icegram Engage<=3.1.24
Remediation
Information
Update to 3.1.25 or a higher version.
Event History
Nov 1, 2024
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-39625?
The severity of CVE-2024-39625 is considered high due to the potential for unauthorized access to functionality.
2
How do I fix CVE-2024-39625?
To fix CVE-2024-39625, upgrade Icegram to version 3.1.25 or later, which addresses this missing authorization vulnerability.
3
What functionality is affected by CVE-2024-39625?
CVE-2024-39625 affects the access control list (ACL) management, allowing unauthorized access to certain functionalities.
4
Which versions of Icegram are vulnerable to CVE-2024-39625?
Icegram versions from n/a through 3.1.24 are vulnerable to CVE-2024-39625.
5
Is CVE-2024-39625 related to WordPress?
Yes, CVE-2024-39625 also affects the Icegram Engage plugin for WordPress up to version 3.1.24.