CVE-2024-4745: WordPress Giveaways and Contests by RafflePress plugin <= 1.12.4 - Broken Access Control vulnerability
Missing Authorization vulnerability in RafflePress Giveaways and Contests by RafflePress.This issue affects Giveaways and Contests by RafflePress: from n/a through 1.12.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Giveaways and Contests by RafflePressto a version that resolves this vulnerability.Fixed in 1.12.5
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4745?
CVE-2024-4745 is classified as a high-severity vulnerability due to the potential for unauthorized access.
How do I fix CVE-2024-4745?
To mitigate CVE-2024-4745, update the RafflePress Giveaways and Contests plugin to version 1.12.5 or later.
What versions are affected by CVE-2024-4745?
CVE-2024-4745 affects all versions of the RafflePress Giveaways and Contests plugin from n/a to 1.12.4.
What type of vulnerability is CVE-2024-4745?
CVE-2024-4745 is a missing authorization vulnerability that may allow attackers to access restricted features.
Who should be concerned about CVE-2024-4745?
Website owners using the RafflePress Giveaways and Contests plugin prior to version 1.12.5 should be concerned about CVE-2024-4745.