WordPress Meta Box plugin <= 5.9.10 - Broken Access Control vulnerability
CVE-2024-43235

7.1HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
1 November 2024

Summary

A vulnerability exists in the MetaBox.Io Meta Box – WordPress Custom Fields Framework due to missing authorization mechanisms. This flaw allows unauthorized access by exploiting incorrectly configured access control security levels, potentially enabling malicious actors to interact with functionalities that should require higher levels of permissions. The vulnerability affects all versions from n/a through 5.9.10, raising concerns for site administrators regarding the risks posed to sensitive data and user interactions. Users are advised to assess their current configurations and apply necessary updates to mitigate potential exploitation.

Affected Version(s)

Meta Box – WordPress Custom Fields Framework <= 5.9.10

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.