WordPress Depicter plugin <= 3.2.2 - Broken Access Control vulnerability
CVE-2024-47359
9.8CRITICAL
Summary
A vulnerability in the Depicter Slider created by Averta presents a significant risk due to missing authorization controls. This flaw allows unauthorized users to gain access to functionalities that should be restricted through proper Access Control Lists (ACLs). All versions from n/a up to 3.2.2 are affected, leading to potential exposure of sensitive operations and data. It's crucial for users relying on the Depicter Slider to address this security oversight to ensure their applications are secure against unauthorized access.
Affected Version(s)
Depicter Slider <= 3.2.2
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rafie Muhammad (Patchstack)