CVE-2024-47318: WordPress PWA for WP & AMP plugin <= 1.7.72 - Broken Access Control vulnerability
Published Nov 1, 2024
·Updated
Missing Authorization vulnerability in Magazine3 PWA for WP & AMP pwa-for-wp.This issue affects PWA for WP & AMP: from n/a through <= 1.7.72.
Affected Software
1 affected component
Magazine3 Pwa For Wp \& Amp Wordpress<1.7.73
Remediation
Information
Update to 1.7.73 or a higher version.
Event History
Nov 1, 2024
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-47318?
CVE-2024-47318 is classified as a missing authorization vulnerability with a critical impact on security.
2
How do I fix CVE-2024-47318?
To fix CVE-2024-47318, update the PWA for WP & AMP plugin to version 1.7.73 or later.
3
What systems are affected by CVE-2024-47318?
CVE-2024-47318 affects all versions of the PWA for WP & AMP plugin from n/a up to 1.7.72.
4
What type of vulnerability is CVE-2024-47318?
CVE-2024-47318 is a missing authorization vulnerability due to incorrectly configured access control security levels.
5
Can CVE-2024-47318 lead to data exposure?
Yes, CVE-2024-47318 can potentially allow unauthorized access to sensitive information.