CVE-2024-51666: WordPress Tours plugin <= 1.0.0 - Broken Access Control vulnerability
Missing Authorization vulnerability in Automattic Tours.This issue affects Tours: from n/a through 1.0.0.
Other sources
Missing Authorization vulnerability in Tosin Oguntuyi Tours tours.This issue affects Tours: from n/a through <= 1.0.0.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-51666?
CVE-2024-51666 has been classified as a high severity vulnerability due to missing authorization controls.
How do I fix CVE-2024-51666?
To fix CVE-2024-51666, update Automattic Tours to the latest version beyond 1.0.0 where the vulnerability has been addressed.
What are the potential impacts of CVE-2024-51666?
The impact of CVE-2024-51666 includes unauthorized access to restricted features and sensitive information within the Tours plugin.
Which versions of Automattic Tours are affected by CVE-2024-51666?
CVE-2024-51666 affects Automattic Tours versions up to and including 1.0.0.
Is CVE-2024-51666 applicable to WordPress Tours as well?
Yes, CVE-2024-51666 is also applicable to WordPress Tours versions up to and including 1.0.0.