CVE-2024-43954: WordPress Droip plugin < 2.5.2 - Settings Change vulnerability
Published Aug 29, 2024
·Updated
Missing Authorization vulnerability in Themeum Droip droip allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Droip: from n/a through < 2.5.2.
Affected Software
1 affected component
Themeum Droip Wordpress<=1.1.1
Event History
Aug 29, 2024
CVE Published
via MITRE·03:18 PM
Data Sourced
via MITRE·03:18 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-43954?
CVE-2024-43954 has a medium severity rating due to its incorrect authorization vulnerability that could allow unauthorized access to features.
2
How do I fix CVE-2024-43954?
To fix CVE-2024-43954, update the Themeum Droip plugin to the latest version that resolves the ACL issues.
3
What versions of Droip are affected by CVE-2024-43954?
CVE-2024-43954 affects all versions of Droip from n/a through 1.1.1.
4
What kind of functionality can be accessed due to CVE-2024-43954?
CVE-2024-43954 allows access to functionalities that are not properly constrained by Access Control Lists (ACLs), potentially exposing sensitive data.
5
Is CVE-2024-43954 specific to WordPress?
Yes, CVE-2024-43954 specifically affects the Themeum Droip plugin used in WordPress.