Missing Authorization Vulnerability in BAKKBONE FloristPress Plugin
CVE-2024-53798

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 December 2024

What is CVE-2024-53798?

A missing authorization vulnerability has been identified in the BAKKBONE FloristPress plugin, impacting versions up to 7.3.0. This issue arises from insufficient access controls, allowing unauthorized users to perform actions intended for authenticated users. The flaw could potentially lead to unauthorized access to sensitive functionalities, posing a risk to website security and data integrity. It's essential for users of FloristPress to update to the latest version to mitigate this vulnerability and enhance their website's protection.

Affected Version(s)

FloristPress 0 <= 7.3.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.