CVE-2024-43998
MEDIUMWebsiteinwp Blogpoet < 1.0.4 - Missing Authorization
Title source: ruleDescription
Missing Authorization vulnerability in WebsiteinWP Blogpoet allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Blogpoet: from n/a through 1.0.3.
Exploits (3)
nomisec
WORKING POC
1 stars
by RandomRobbieBF · poc
https://github.com/RandomRobbieBF/CVE-2024-43998
github
WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2024-43998
Scores
CVSS v3
6.5
EPSS
0.2596
EPSS Percentile
96.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Classification
CWE
CWE-862
Status
published
Affected Products (1)
websiteinwp/blogpoet
< 1.0.4
Timeline
Published
Nov 01, 2024
Tracked Since
Feb 18, 2026