CVE-2024-39634: WordPress PowerPack Pro for Elementor plugin <= 2.10.14 - Contributor+ Privilege Escalation vulnerability
Published Aug 1, 2024
·Updated
Improper Privilege Management vulnerability in IdeaBox PowerPack Pro for Elementor allows Privilege Escalation.This issue affects PowerPack Pro for Elementor: from n/a through 2.10.14.
Affected Software
2 affected components
IdeaBox PowerPack Pro for Elementor<=2.10.14
WordPress PowerPack Pro for Elementor<=2.10.14
Remediation
Information
Update to 2.10.15 or a higher version.
Event History
Aug 1, 2024
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-39634?
CVE-2024-39634 has been classified as a critical severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2024-39634?
To resolve CVE-2024-39634, update the IdeaBox PowerPack Pro for Elementor plugin to version 2.10.15 or later.
3
Which versions of PowerPack Pro for Elementor are affected by CVE-2024-39634?
CVE-2024-39634 affects PowerPack Pro for Elementor versions from n/a up to 2.10.14.
4
What kind of issue is CVE-2024-39634?
CVE-2024-39634 is an improper privilege management issue that allows for privilege escalation within the affected plugin.
5
Who is the vendor for CVE-2024-39634?
The vendor for CVE-2024-39634 is IdeaBox, the developer of PowerPack Pro for Elementor.