PT-2024-30418 · WordPress · Leopard - Wordpress Offload Media

Dave Jong

·

Published

2024-08-19

·

Updated

2024-08-23

·

CVE-2024-43256

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Leopard - WordPress offload media versions prior to 2.0.37
Description The issue is related to a missing authorization vulnerability in Leopard - WordPress offload media, which allows accessing functionality not properly constrained by ACLs. This could potentially allow an attacker to gain elevated privileges.
Recommendations For versions prior to 2.0.37, update the plugin to the latest version immediately to resolve the issue. As a temporary workaround, consider restricting access to sensitive functionality until the update is applied.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-43256

Affected Products

Leopard - Wordpress Offload Media