CVE-2024-43973: WordPress GetPaid plugin <= 2.8.11 - Broken Access Control vulnerability
Published Nov 1, 2024
·Updated
Missing Authorization vulnerability in Stiofan GetPaid invoicing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GetPaid: from n/a through <= 2.8.11.
Affected Software
1 affected component
AyeCode Getpaid Wordpress<2.8.12
Remediation
Information
Update to 2.8.12 or a higher version.
Event History
Nov 1, 2024
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-43973?
The severity of CVE-2024-43973 is classified as high due to the potential for unauthorized access to sensitive data.
2
How do I fix CVE-2024-43973?
To fix CVE-2024-43973, upgrade AyeCode GetPaid to version 2.8.12 or later to ensure proper access control is enforced.
3
What systems are affected by CVE-2024-43973?
CVE-2024-43973 affects AyeCode GetPaid versions from n/a through 2.8.11.
4
What details are available about CVE-2024-43973?
CVE-2024-43973 involves a missing authorization vulnerability allowing exploitation due to incorrectly configured access controls.
5
Can CVE-2024-43973 be exploited remotely?
Yes, CVE-2024-43973 can be exploited remotely if the affected version is publicly accessible.