CVE-2024-43331: WordPress WP SMS plugin <= 6.9.3 - Broken Access Control vulnerability
Published Aug 22, 2024
·Updated
Missing Authorization vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.9.3.
Affected Software
3 affected components
VeronaLabs Wp Sms Wordpress<6.9.4
VeronaLabs WP SMS<=6.9.3
WordPress WP SMS<=6.9.3
Remediation
Information
Update to 6.9.4 or a higher version.
Event History
Aug 22, 2024
CVE Published
via MITRE·11:29 AM
Data Sourced
via MITRE·11:29 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-43331?
CVE-2024-43331 has a high severity due to the missing authorization vulnerability that can lead to unauthorized access.
2
How do I fix CVE-2024-43331?
To fix CVE-2024-43331, update the WP SMS plugin to version 6.9.4 or later.
3
What versions of WP SMS are affected by CVE-2024-43331?
CVE-2024-43331 affects WP SMS from version n/a up to and including 6.9.3.
4
What kind of vulnerability is CVE-2024-43331?
CVE-2024-43331 is categorized as a missing authorization vulnerability.
5
Is there a workaround for CVE-2024-43331?
Currently, the best approach is to update to a patched version, as there are no known workarounds for CVE-2024-43331.