Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-44220 | The AppPresser plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'decrypt_value' and on the 'doCookieAuth' functions in all versions up to, and including, 4.3.2. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they previously used the login via the plugin API. This can only be exploited if the 'openssl' php extension is not loaded on the server. |
Wed, 08 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-703 |
Thu, 05 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apppresser
Apppresser apppresser |
|
| Weaknesses | CWE-754 | |
| CPEs | cpe:2.3:a:apppresser:apppresser:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Apppresser
Apppresser apppresser |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:25:08.103Z
Reserved: 2024-05-07T14:59:27.872Z
Link: CVE-2024-4611
Updated: 2024-08-01T20:47:41.366Z
Status : Modified
Published: 2024-05-29T05:16:08.603
Modified: 2026-04-08T19:21:42.733
Link: CVE-2024-4611
No data.
OpenCVE Enrichment
No data.
EUVD