CVE-2024-49321: WordPress Simple Custom Post Order plugin <= 2.5.7 - Broken Access Control vulnerability
Missing Authorization vulnerability in colorlibplugins Simple Custom Post Order simple-custom-post-order allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Custom Post Order: from n/a through <= 2.5.7.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49321?
The severity of CVE-2024-49321 is considered high due to the risk of unauthorized access and potential data exposure.
How do I fix CVE-2024-49321?
To fix CVE-2024-49321, update the Simple Custom Post Order plugin to version 2.5.8 or later.
What does CVE-2024-49321 affect?
CVE-2024-49321 affects versions of the Colorlib Simple Custom Post Order plugin from n/a to 2.5.7 on WordPress.
Who is affected by CVE-2024-49321?
Users of the Colorlib Simple Custom Post Order plugin who have not upgraded beyond version 2.5.7 are affected by CVE-2024-49321.
What actions can exploit CVE-2024-49321?
An attacker can exploit CVE-2024-49321 by leveraging incorrectly configured access control security levels to gain unauthorized access.