WordPress Meta Box plugin <= 5.9.10 - Broken Access Control vulnerability
CVE-2024-43235
7.1HIGH
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 1 November 2024
What is CVE-2024-43235?
A vulnerability exists in the MetaBox.Io Meta Box – WordPress Custom Fields Framework due to missing authorization mechanisms. This flaw allows unauthorized access by exploiting incorrectly configured access control security levels, potentially enabling malicious actors to interact with functionalities that should require higher levels of permissions. The vulnerability affects all versions from n/a through 5.9.10, raising concerns for site administrators regarding the risks posed to sensitive data and user interactions. Users are advised to assess their current configurations and apply necessary updates to mitigate potential exploitation.
Affected Version(s)
Meta Box – WordPress Custom Fields Framework <= 5.9.10