plugin

Listapp Mobile Manager Vulnerabilities

2 known security issues reported for the Listapp Mobile Manager WordPress plugin. Most recent disclosed Dec 13, 2024.

1 critical

Running Listapp Mobile Manager on your site? Check whether your installed version is affected.

Scan your site free

ListApp Mobile Manager [listapp-mobile-manager] <= 1.7.7 (unfixed + closed)

unknown

[en] Authentication Bypass Using an Alternate Path or Channel vulnerability in InspireUI ListApp Mobile Manager allows Authentication Bypass.This issue affects ListApp Mobile Manager: from n/a through 1.7.7.

Affected:
up to 1.7.7
Fix:
No patched version reported
Disclosed:
Dec 13, 2024

CVE-2024-54295 on NVD →

ListApp Mobile Manager <= 1.7.7 - Missing Authorization to Privilege Escalation

critical

The ListApp Mobile Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.7.7. This makes it possible for unauthenticated attackers to elevate their privilege level and gain access to administrator accounts.

CVSS:
9.8
Affected:
up to 1.7.7
Fix:
No patched version reported
Disclosed:
Dec 11, 2024

CVE-2024-54295 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database