Permalink
CVE-2024-56007
4.3 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): LOW
- Availability impact (A): NONE
WordPress Leader plugin <= 2.6.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in Ram Segev Leader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Leader: from n/a through 2.6.1.
References
Affected products
leader
- =<2.6.1
Matching in nixpkgs
pkgs.emacsPackages.leader-key
None
-
nixos-unstable 20231001.2236
- nixpkgs-unstable 20231001.2236
- nixos-unstable-small 20231001.2236
pkgs.emacsPackages.evil-leader
None
-
nixos-unstable 20140606.1243
- nixpkgs-unstable 20140606.1243
- nixos-unstable-small 20140606.1243
pkgs.vimPlugins.vim-leader-guide
None
-
nixos-unstable 2018-10-06
- nixpkgs-unstable 2018-10-06
- nixos-unstable-small 2018-10-06