CVE-2024-43288: WordPress wpForo Forum plugin <= 2.3.4 - Insecure Direct Object References (IDOR) vulnerability
Published Aug 18, 2024
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from n/a through 2.3.4.
Affected Software
3 affected components
gVectors Wpforo Forum Wordpress<2.3.5
gVectors Team wpForo Forum<=2.3.4
WordPress wpForo Forum<=2.3.4
Remediation
Information
Update to 2.3.5 or a higher version.
Event History
Aug 18, 2024
CVE Published
via MITRE·09:33 PM
Data Sourced
via MITRE·09:33 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
May 26, 57072
Event
via NVD·03:26 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-43288?
CVE-2024-43288 is classified as a medium severity vulnerability that allows for authorization bypass.
2
How do I fix CVE-2024-43288?
To fix CVE-2024-43288, update wpForo Forum to version 2.3.5 or later.
3
What versions of wpForo Forum are affected by CVE-2024-43288?
CVE-2024-43288 affects wpForo Forum versions up to and including 2.3.4.
4
What type of vulnerability is CVE-2024-43288?
CVE-2024-43288 is an authorization bypass vulnerability that can be exploited through user-controlled keys.
5
Is there an exploit available for CVE-2024-43288?
While the specific details of any exploit are not provided, CVE-2024-43288 does represent a risk that could be exploited given the nature of the vulnerability.