PT-2024-23919 · WordPress · Embedpress

Mika

·

Published

2024-06-09

·

Updated

2024-11-01

·

CVE-2024-31274

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions EmbedPress versions 3.9.11 and earlier
Description A Missing Authorization issue affects the EmbedPress plugin, potentially allowing unauthorized access. The estimated number of affected devices is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations For EmbedPress versions 3.9.11 and earlier, update to a version later than 3.9.11 to resolve the issue. At the moment, there is no information about additional mitigation measures for this vulnerability.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-31274

Affected Products

Embedpress