First published: Tue Nov 19 2024(Updated: )
Missing Authorization vulnerability in Rextheme WP VR allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP VR: from n/a through 8.5.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rextheme WP VR | >=8.5.5 | |
WordPress | <=8.5.5 |
Update to 8.5.6 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49680 is classified as a missing authorization vulnerability which can lead to improper access control.
To fix CVE-2024-49680, update Rextheme WP VR to the latest version that addresses this vulnerability.
CVE-2024-49680 affects Rextheme WP VR versions from n/a up to and including 8.5.5.
CVE-2024-49680 allows for exploitation due to incorrectly configured access control security levels.
CVE-2024-49680 specifically affects the Rextheme WP VR plugin used within WordPress.