CVE-2024-43235: WordPress Meta Box plugin <= 5.9.10 - Broken Access Control vulnerability
Missing Authorization vulnerability in MetaBox.Io Meta Box – WordPress Custom Fields Framework allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Meta Box – WordPress Custom Fields Framework: from n/a through 5.9.10.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43235?
CVE-2024-43235 has been classified as a high severity vulnerability due to its potential to exploit access control misconfigurations.
How do I fix CVE-2024-43235?
To fix CVE-2024-43235, update the Meta Box – WordPress Custom Fields Framework to version 5.9.11 or later.
What does CVE-2024-43235 affect?
CVE-2024-43235 affects the Meta Box – WordPress Custom Fields Framework versions up to and including 5.9.10.
What type of vulnerability is CVE-2024-43235?
CVE-2024-43235 is a Missing Authorization vulnerability that allows attackers to exploit improperly configured access controls.
Who is impacted by CVE-2024-43235?
Users and administrators of the Meta Box plugin for WordPress versions up to 5.9.10 are impacted by CVE-2024-43235.