Missing Authorization vulnerability in Upqode Plum: Spin Wheel & Email Pop-up allows Accessing Functionality Not Properly Constrained by ACLs, Stored XSS.This issue affects Plum: Spin Wheel & Email Pop-up: from n/a through 2.0.
Metrics
Affected Vendors & Products
References
History
Tue, 05 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Upqode
Upqode plum |
|
CPEs | cpe:2.3:a:upqode:plum:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Upqode
Upqode plum |
|
Metrics |
ssvc
|
Fri, 01 Nov 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Missing Authorization vulnerability in Upqode Plum: Spin Wheel & Email Pop-up allows Accessing Functionality Not Properly Constrained by ACLs, Stored XSS.This issue affects Plum: Spin Wheel & Email Pop-up: from n/a through 2.0. | |
Title | WordPress Plum: Spin Wheel & Email Pop-up plugin <= 2.0 - Broken Access Control to Unauth Stored XSS vulnerability | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Patchstack
Published: 2024-11-01T14:18:01.123Z
Updated: 2024-11-05T15:28:35.401Z
Reserved: 2024-06-19T11:16:57.418Z
Link: CVE-2024-38744
Vulnrichment
Updated: 2024-11-05T15:28:28.408Z
NVD
Status : Awaiting Analysis
Published: 2024-11-01T15:15:34.043
Modified: 2024-11-01T20:24:53.730
Link: CVE-2024-38744
Redhat
No data.