CVE-2024-43968: WordPress Newspack plugin < 3.8.7 - Broken Access Control vulnerability
Published Nov 1, 2024
·Updated
Broken Access Control vulnerability in Automattic Newspack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Newspack: from n/a through 3.8.6.
Affected Software
1 affected component
Automattic Newspack Wordpress<3.8.7
Remediation
Information
Update to 3.8.7 or a higher version.
Event History
Nov 1, 2024
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-43968?
CVE-2024-43968 has a critical severity due to broken access control that could allow unauthorized access to sensitive data.
2
How do I fix CVE-2024-43968?
To fix CVE-2024-43968, update Newspack to version 3.8.7 or later.
3
What versions of Newspack are affected by CVE-2024-43968?
CVE-2024-43968 affects all versions of Newspack up to and including 3.8.6.
4
What type of vulnerability is CVE-2024-43968?
CVE-2024-43968 is a Broken Access Control vulnerability.
5
Can CVE-2024-43968 be exploited remotely?
Yes, CVE-2024-43968 can be exploited remotely due to misconfigured access control settings.