CVE-2024-43212: WordPress WpTravelly plugin <= 1.7.7 - Broken Access Control vulnerability
Missing Authorization vulnerability in MagePeople Team WpTravelly allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WpTravelly: from n/a through 1.7.7.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43212?
CVE-2024-43212 is rated as a high severity vulnerability due to its potential to allow unauthorized access to critical functionality.
How do I fix CVE-2024-43212?
To fix CVE-2024-43212, update the WpTravelly plugin to version 1.7.8 or later where the issue has been patched.
What systems are affected by CVE-2024-43212?
CVE-2024-43212 affects versions of the WpTravelly plugin up to and including 1.7.7.
What type of vulnerability is CVE-2024-43212?
CVE-2024-43212 is categorized as a missing authorization vulnerability, specifically related to broken access control.
Can CVE-2024-43212 be exploited remotely?
Yes, CVE-2024-43212 can be exploited remotely, allowing attackers to access restricted functionality without proper authorization.