This issue affects WP Free SSL – Free SSL Certificate for WordPress and force HTTPS: from n/a through 1.2.6.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-40802 | Missing Authorization vulnerability in Prasad Kirpekar WP Free SSL – Free SSL Certificate for WordPress and force HTTPS allows . This issue affects WP Free SSL – Free SSL Certificate for WordPress and force HTTPS: from n/a through 1.2.6. |
Solution
Deactivate and delete. This plugin has been closed as of October 3, 2024 and is not available for download. This closure is temporary, pending a full review
Workaround
No workaround given by the vendor.
Fri, 08 Nov 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Prasadkirpekar
Prasadkirpekar wp Free Ssl |
|
| CPEs | cpe:2.3:a:prasadkirpekar:wp_free_ssl:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Prasadkirpekar
Prasadkirpekar wp Free Ssl |
Mon, 04 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 01 Nov 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing Authorization vulnerability in Prasad Kirpekar WP Free SSL – Free SSL Certificate for WordPress and force HTTPS allows . This issue affects WP Free SSL – Free SSL Certificate for WordPress and force HTTPS: from n/a through 1.2.6. | |
| Title | WordPress WP Free SSL plugin <= 1.2.6 - Broken Access Control vulnerability | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2024-11-04T18:09:14.803Z
Reserved: 2024-08-18T21:58:06.273Z
Link: CVE-2024-44020
Updated: 2024-11-04T18:09:11.005Z
Status : Analyzed
Published: 2024-11-01T15:15:52.483
Modified: 2024-11-08T21:02:41.617
Link: CVE-2024-44020
No data.
OpenCVE Enrichment
No data.
EUVD