CVE-2024-43273: WordPress Icegram Collect plugin <= 1.3.14 - Broken Access Control vulnerability
Missing Authorization vulnerability in icegram Icegram Collect plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Icegram Collect plugin: from n/a through 1.3.14.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43273?
CVE-2024-43273 is classified as a missing authorization vulnerability that can lead to unauthorized access due to incorrectly configured access control security levels.
How do I fix CVE-2024-43273?
To fix CVE-2024-43273, update the Icegram Collect plugin to version 1.3.15 or later to ensure proper access control is enforced.
Who is affected by CVE-2024-43273?
CVE-2024-43273 affects users of the Icegram Collect plugin versions up to and including 1.3.14.
What does CVE-2024-43273 allow an attacker to do?
CVE-2024-43273 allows an attacker to exploit improperly configured access controls potentially leading to unauthorized actions within the Icegram Collect plugin.
Is the Icegram Collect plugin safe to use after CVE-2024-43273?
The Icegram Collect plugin is safe to use as long as it is updated to the latest version that addresses CVE-2024-43273.