CVE-2024-43289: WordPress wpForo Forum plugin <= 2.3.4 - Unauthenticated Sensitive Data Exposure vulnerability
Published Aug 26, 2024
·Updated
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from n/a through 2.3.4.
Affected Software
3 affected components
gVectors Wpforo Forum Wordpress<2.3.5
gVectors Team wpForo Forum<=2.3.4
WordPress wpForo Forum<=2.3.4
Remediation
Information
Update to 2.3.5 or a higher version.
Event History
Aug 26, 2024
CVE Published
via MITRE·04:06 PM
Data Sourced
via MITRE·04:06 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-43289?
CVE-2024-43289 has a moderate severity level due to the exposure of sensitive information.
2
How do I fix CVE-2024-43289?
To fix CVE-2024-43289, update the wpForo Forum plugin to version 2.3.5 or later.
3
What types of sensitive information are exposed in CVE-2024-43289?
CVE-2024-43289 exposes sensitive user data to unauthorized actors.
4
Which versions of wpForo Forum are affected by CVE-2024-43289?
CVE-2024-43289 affects all versions of wpForo Forum up to and including 2.3.4.
5
Is there a workaround for CVE-2024-43289?
There is no official workaround for CVE-2024-43289; updating the plugin is recommended.