WordPress Depicter plugin <= 3.2.2 - Broken Access Control vulnerability
CVE-2024-47359

9.8CRITICAL

Key Information:

Vendor
WordPress
Vendor
CVE Published:
1 November 2024

Summary

A vulnerability in the Depicter Slider created by Averta presents a significant risk due to missing authorization controls. This flaw allows unauthorized users to gain access to functionalities that should be restricted through proper Access Control Lists (ACLs). All versions from n/a up to 3.2.2 are affected, leading to potential exposure of sensitive operations and data. It's crucial for users relying on the Depicter Slider to address this security oversight to ensure their applications are secure against unauthorized access.

Affected Version(s)

Depicter Slider <= 3.2.2

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.