CVE-2024-56238: WordPress Floating Action Buttons plugin <= 0.9.1 - Broken Access Control vulnerability
Published Jan 2, 2025
·Updated
Missing Authorization vulnerability in QuantumCloud Floating Action Buttons floating-action-buttons allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Floating Action Buttons: from n/a through <= 0.9.1.
Affected Software
1 affected component
QuantumCloud Floating Action Buttons<=0.9.1
Remediation
Information
Update the WordPress Floating Action Buttons plugin to the latest available version (at least 1.0.1).
Event History
Jan 2, 2025
CVE Published
via MITRE·12:01 PM
Data Sourced
via MITRE·12:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-56238?
The severity of CVE-2024-56238 is identified as high due to missing authorization controls.
2
How do I fix CVE-2024-56238?
To fix CVE-2024-56238, upgrade the Floating Action Buttons plugin to a patched version above 0.9.1.
3
Which versions are affected by CVE-2024-56238?
CVE-2024-56238 affects all versions of Floating Action Buttons from n/a up to and including 0.9.1.
4
What type of vulnerability is CVE-2024-56238?
CVE-2024-56238 is classified as a missing authorization vulnerability.
5
Who is affected by CVE-2024-56238?
Users of QuantumCloud and WordPress Floating Action Buttons versions up to 0.9.1 are affected by CVE-2024-56238.