First published: Thu Aug 29 2024(Updated: )
Incorrect Authorization vulnerability in Themeum Droip allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Droip: from n/a through 1.1.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Themeum Droip | <=1.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-43954 has a medium severity rating due to its incorrect authorization vulnerability that could allow unauthorized access to features.
To fix CVE-2024-43954, update the Themeum Droip plugin to the latest version that resolves the ACL issues.
CVE-2024-43954 affects all versions of Droip from n/a through 1.1.1.
CVE-2024-43954 allows access to functionalities that are not properly constrained by Access Control Lists (ACLs), potentially exposing sensitive data.
Yes, CVE-2024-43954 specifically affects the Themeum Droip plugin used in WordPress.