PT-2024-30418 · WordPress · Leopard - Wordpress Offload Media
Dave Jong
·
Published
2024-08-19
·
Updated
2024-08-23
·
CVE-2024-43256
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Leopard - WordPress offload media versions prior to 2.0.37
Description
The issue is related to a missing authorization vulnerability in Leopard - WordPress offload media, which allows accessing functionality not properly constrained by ACLs. This could potentially allow an attacker to gain elevated privileges.
Recommendations
For versions prior to 2.0.37, update the plugin to the latest version immediately to resolve the issue. As a temporary workaround, consider restricting access to sensitive functionality until the update is applied.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Leopard - Wordpress Offload Media