CVE Database /
CVE-2024-43235
CVE · High
CVE-2024-43235 — Meta Box [meta-box] < 5.9.11
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-43235
|
Meta Box [meta-box] < 5.9.11 |
Missing Authorization |
High
7.1
|
< 5.9.11
|
5.9.11 |
2024-08-09 |
—
|
CVE-2024-43235
The Meta Box plugin before version 5.9.11 contains an authorization flaw in its ajax_get_posts function that fails to verify user capabilities. Authenticated users with contributor privileges or higher can exploit this vulnerability to access and view any posts in the WordPress installation without proper permission checks. The issue affects all versions up through 5.9.10 and is resolved in version 5.9.11.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings