PT-2024-37295 · WordPress · Wp Accessibility Helper

Lucio Sá

·

Published

2024-08-28

·

Updated

2024-10-04

·

CVE-2024-5987

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions: WP Accessibility Helper plugin versions prior to 0.6.2.8
Description: The issue allows authenticated attackers with Subscriber-level access and above to edit or delete contrast settings due to a missing capability check on the save contrast variations and save empty contrast variations functions.
Recommendations: For versions prior to 0.6.2.8, as a temporary workaround, consider disabling the save contrast variations and save empty contrast variations functions until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-5987

Affected Products

Wp Accessibility Helper