4.3

CVE-2024-2543

Exploit

Plugin Permalink <= 2.4.3.1 - Missing Authorization via get_uri_editor

The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_uri_editor' function in all versions up to, and including, 2.4.3.1. This makes it possible for unauthenticated attackers to view the permalinks of all posts.
Mögliche Gegenmaßnahme
Permalink Manager Lite: Update to version 2.4.3.2, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Permalink Manager Lite
Version *-2.4.3.1
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Permalink Manager Lite ProjectPermalink Manager Lite SwPlatformwordpress Version < 2.4.3.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.5% 0.654
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@wordfence.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.