CVE-2024-43153: WordPress Woffice theme <= 5.4.10 - Unauthenticated Privilege Escalation vulnerability
Published Aug 13, 2024
·Updated
Incorrect Privilege Assignment vulnerability in WofficeIO Woffice woffice.This issue affects Woffice: from n/a through <= 5.4.10.
Affected Software
3 affected components
WofficeIO Woffice<=5.4.10
WordPress Woffice<=5.4.10
Xtendify Woffice Wordpress<5.4.12
Remediation
Information
Update to 5.4.12 or a higher version.
Event History
Aug 13, 2024
CVE Published
via MITRE·11:39 AM
Data Sourced
via MITRE·11:39 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-43153?
CVE-2024-43153 is classified as a high-severity vulnerability due to its potential for privilege escalation.
2
Who is affected by CVE-2024-43153?
CVE-2024-43153 affects Woffice version up to 5.4.10 and is also relevant to WordPress installations using the Woffice theme.
3
How do I fix CVE-2024-43153?
To fix CVE-2024-43153, upgrade Woffice to the latest version released after 5.4.10.
4
What type of vulnerability is CVE-2024-43153?
CVE-2024-43153 is an improper privilege management vulnerability that allows for privilege escalation.
5
Can CVE-2024-43153 be exploited remotely?
Yes, CVE-2024-43153 can be exploited remotely without authentication, posing a significant risk to affected installations.