WordPress Ads by WPQuads plugin <= 2.0.84 - Broken Access Control vulnerability
CVE-2024-47317

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 November 2024

What is CVE-2024-47317?

The vulnerability present in the Ads by WPQuads – Adsense Ads, Banner Ads, Popup Ads enables unauthorized access due to incorrectly configured access control security levels. This flaw affects versions from unspecified up to 2.0.84, allowing potential attackers to exploit the inadequate authorization checks. As a result, sensitive operations may be executed without proper user permissions, increasing the risk of data exposure and manipulation within the affected products.

Affected Version(s)

Ads by WPQuads 0 <= 2.0.84

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Trương Hữu Phúc (truonghuuphuc) (Patchstack Alliance)
.