CVE-2024-39635: WordPress Youzify plugin <= 1.2.6 - Broken Access Control vulnerability
Missing Authorization vulnerability in KaineLabs Youzify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Youzify: from n/a through 1.2.6.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39635?
CVE-2024-39635 is categorized as a high severity vulnerability due to its potential to exploit incorrect access control configurations.
How do I fix CVE-2024-39635?
To fix CVE-2024-39635, update the KaineLabs Youzify plugin to the latest version beyond 1.2.6 to ensure proper access control configurations.
What versions are affected by CVE-2024-39635?
CVE-2024-39635 affects all versions of the KaineLabs Youzify plugin from n/a through 1.2.6.
What types of attacks are possible with CVE-2024-39635?
Potential attacks with CVE-2024-39635 include unauthorized access to restricted resources or information due to misconfigured access controls.
Is there a specific mitigation strategy for CVE-2024-39635?
Yes, auditing access control settings and promptly updating to the latest secure version of the Youzify plugin are key mitigation strategies.