PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-24709 Shareaholic CVE debrief

The CVE-2024-24709 vulnerability is a Missing Authorization issue in the Shareaholic plugin, which could allow attackers to exploit incorrectly configured access control security levels. This vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity. The affected versions of Shareaholic range from n/a to 9.7.11. Users should be cautious and take necessary actions to mitigate this vulnerability.

Vendor
Shareaholic
Product
Unknown
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-17
Original CVE updated
2026-06-17
Advisory published
2026-06-17
Advisory updated
2026-06-17

Who should care

Administrators and users of the Shareaholic plugin, especially those using versions from n/a to 9.7.11, should be aware of this vulnerability and take necessary actions to secure their installations.

Technical summary

The CVE-2024-24709 vulnerability is caused by a Missing Authorization issue in the Shareaholic plugin. This allows attackers to exploit incorrectly configured access control security levels. The vulnerability has a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N and is classified as CWE-862. The affected versions of Shareaholic range from n/a to 9.7.11.

Defensive priority

MEDIUM

Recommended defensive actions

  • Update Shareaholic plugin to the latest version
  • Review and configure access control security levels properly
  • Monitor plugin usage and access logs for suspicious activity
  • Implement additional security measures, such as authentication and authorization checks
  • Consider using a Web Application Firewall (WAF) to detect and prevent attacks
  • Regularly update and patch plugins and software
  • Perform regular security audits and vulnerability assessments

Evidence notes

The information provided is based on the CVE-2024-24709 record and the NVD detail page. The vulnerability was reported by [email protected] and has a trust class of official_vulnerability_database.

Official resources

CVE-2024-24709 was published on 2026-06-17T13:19:10.807Z and modified on 2026-06-17T17:16:36.633Z.