CVE-2024-43277: WordPress UsersWP plugin <= 1.2.15 - Broken Access Control vulnerability
Published Nov 1, 2024
·Updated
Missing Authorization vulnerability in AyeCode Ltd UsersWP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through 1.2.15.
Affected Software
2 affected components
AyeCode Ltd UsersWP<=1.2.15
WordPress UsersWP<=1.2.15
Remediation
Information
Update to 1.2.16 or a higher version.
Event History
Nov 1, 2024
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-43277?
CVE-2024-43277 is classified as a Missing Authorization vulnerability that can lead to improper access control.
2
How do I fix CVE-2024-43277?
To fix CVE-2024-43277, upgrade your AyeCode Ltd UsersWP plugin to the latest version above 1.2.15.
3
What versions of UsersWP are affected by CVE-2024-43277?
CVE-2024-43277 affects AyeCode Ltd UsersWP versions from n/a up to and including 1.2.15.
4
What can attackers achieve by exploiting CVE-2024-43277?
Attackers can exploit CVE-2024-43277 to gain unauthorized access to sensitive functions within the UsersWP plugin.
5
Is CVE-2024-43277 related to WordPress?
Yes, CVE-2024-43277 affects the UsersWP plugin which is used in WordPress.