PT-2024-30386 · WordPress · Sweet Date

Kursat Cetin

+1

·

Published

2024-12-06

·

Updated

2024-12-20

·

CVE-2024-43222

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sweet Date versions 3.7.3 and earlier
Description The issue is related to a Missing Authorization vulnerability in the Sweet Date WordPress theme, which could expose thousands of sites to potential takeovers. This vulnerability may allow unauthorized access, potentially leading to site compromises. The estimated number of potentially affected devices worldwide is not explicitly stated, but it is mentioned that thousands of sites could be exposed.
Recommendations For Sweet Date versions 3.7.3 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-43222

Affected Products

Sweet Date