Description
Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Defender Security defender-security.This issue affects Defender Security: from n/a through <= 4.7.1.
Published: 2024-11-01
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-36669 Missing Authorization vulnerability in WPMU DEV Defender Security allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Defender Security: from n/a through 4.7.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in WPMU DEV Defender Security allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Defender Security: from n/a through 4.7.1. Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Defender Security defender-security.This issue affects Defender Security: from n/a through <= 4.7.1.
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 28 May 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Wpmudev defender
CPEs cpe:2.3:a:wmpudev:defender_security:*:*:*:*:*:wordpress:*:* cpe:2.3:a:wpmudev:defender:*:*:*:*:free:wordpress:*:*
Vendors & Products Wmpudev
Wmpudev defender Security
Wpmudev defender

Thu, 15 May 2025 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Wmpudev
Wmpudev defender Security
CPEs cpe:2.3:a:wmpudev:defender_security:*:*:*:*:*:wordpress:*:*
Vendors & Products Wmpudev
Wmpudev defender Security

Fri, 01 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Wpmudev
Wpmudev defender Security
CPEs cpe:2.3:a:wpmudev:defender_security:*:*:*:*:*:wordpress:*:*
Vendors & Products Wpmudev
Wpmudev defender Security
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 01 Nov 2024 14:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in WPMU DEV Defender Security allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Defender Security: from n/a through 4.7.1.
Title WordPress Defender plugin <= 4.7.1 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Wpmudev Defender Defender Security
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:09:59.043Z

Reserved: 2024-06-09T08:52:00.673Z

Link: CVE-2024-37444

cve-icon Vulnrichment

Updated: 2024-11-01T18:15:04.650Z

cve-icon NVD

Status : Modified

Published: 2024-11-01T15:15:25.207

Modified: 2026-04-23T15:18:38.243

Link: CVE-2024-37444

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses