Missing Authorization Vulnerability in WP-CRM System
CVE-2024-55991

6.5MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
31 December 2024

Summary

A critical missing authorization vulnerability has been identified in the WP-CRM System, which allows for exploitation of incorrectly configured access control settings. This misconfiguration can lead to unauthorized access to sensitive functionalities within the system. Affected versions include all prior to 3.2.9.1. Organizations using this software should prioritize a comprehensive review of their access control configurations to mitigate the risk of exploitation.

Affected Version(s)

WP-CRM System <= 3.2.9.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mika (Patchstack Alliance)
.
CVE-2024-55991 : Missing Authorization Vulnerability in WP-CRM System | SecurityVulnerability.io