CVE-2024-50417: WordPress Bold Page Builder plugin <= 5.1.3 - Broken Access Control vulnerability
Published Nov 19, 2024
·Updated
Missing Authorization vulnerability in boldthemes Bold Page Builder bold-page-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bold Page Builder: from n/a through <= 5.1.3.
Affected Software
1 affected component
Bold-themes Bold Page Builder Wordpress<5.1.4
Remediation
Information
Update to 5.1.4 or a higher version.
Event History
Nov 19, 2024
CVE Published
via MITRE·04:30 PM
Data Sourced
via MITRE·04:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-50417?
CVE-2024-50417 is classified as having a medium severity due to its potential impact on access control.
2
How do I fix CVE-2024-50417?
To fix CVE-2024-50417, update Bold Page Builder to version 5.1.4 or later.
3
What software is affected by CVE-2024-50417?
CVE-2024-50417 affects Bold Page Builder versions up to 5.1.3, which is used in WordPress.
4
What type of vulnerability is CVE-2024-50417?
CVE-2024-50417 is a missing authorization vulnerability that exploits incorrectly configured access control settings.
5
Can CVE-2024-50417 be exploited easily?
Yes, CVE-2024-50417 can be exploited easily if the affected version is not updated, as it allows unauthorized access.