Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-37592 | Missing Authorization vulnerability in Upqode Plum: Spin Wheel & Email Pop-up allows Accessing Functionality Not Properly Constrained by ACLs, Stored XSS.This issue affects Plum: Spin Wheel & Email Pop-up: from n/a through 2.0. |
Solution
Deactivate and delete. This plugin has been closed as of July 10, 2024 and is not available for download.
Workaround
No workaround given by the vendor.
Tue, 05 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Upqode
Upqode plum |
|
| CPEs | cpe:2.3:a:upqode:plum:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Upqode
Upqode plum |
|
| Metrics |
ssvc
|
Fri, 01 Nov 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing Authorization vulnerability in Upqode Plum: Spin Wheel & Email Pop-up allows Accessing Functionality Not Properly Constrained by ACLs, Stored XSS.This issue affects Plum: Spin Wheel & Email Pop-up: from n/a through 2.0. | |
| Title | WordPress Plum: Spin Wheel & Email Pop-up plugin <= 2.0 - Broken Access Control to Unauth Stored XSS vulnerability | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2024-11-05T15:28:35.401Z
Reserved: 2024-06-19T11:16:57.418Z
Link: CVE-2024-38744
Updated: 2024-11-05T15:28:28.408Z
Status : Awaiting Analysis
Published: 2024-11-01T15:15:34.043
Modified: 2024-11-01T20:24:53.730
Link: CVE-2024-38744
No data.
OpenCVE Enrichment
No data.
EUVD