CVE-2024-43272: WordPress Icegram Engage plugin <= 3.1.24 - Unauthenticated Unpublished Campaign Viewer vulnerability
Published Aug 19, 2024
·Updated
Missing Authentication for Critical Function vulnerability in icegram Icegram allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Icegram: from n/a through 3.1.24.
Affected Software
2 affected components
Icegram Icegram<=3.1.24
WordPress Icegram Engage<=3.1.24
Remediation
Information
Update to 3.1.25 or a higher version.
Event History
Aug 19, 2024
CVE Published
via MITRE·05:43 PM
Data Sourced
via MITRE·05:43 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-43272?
CVE-2024-43272 is classified as a critical vulnerability due to missing authentication for critical functions.
2
How do I fix CVE-2024-43272?
To fix CVE-2024-43272, update Icegram or Icegram Engage to the latest version beyond 3.1.24.
3
What are the potential impacts of CVE-2024-43272?
CVE-2024-43272 can allow unauthorized access to functionalities not properly constrained by access control lists (ACLs).
4
Which versions of Icegram are affected by CVE-2024-43272?
Versions of Icegram up to and including 3.1.24 are affected by CVE-2024-43272.
5
Is CVE-2024-43272 present in Icegram Engage?
Yes, CVE-2024-43272 also affects Icegram Engage up to version 3.1.24.