CVE-2024-38740

WordPress Packlink PRO shipping module plugin <= 3.4.6 - Broken Access Control vulnerability

Missing Authorization vulnerability in Packlink Shipping S.L. Packlink PRO shipping module allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Packlink PRO shipping module: from n/a through 3.4.6.


We have discovered 291 live websites that are affected by CVE-2024-38740.

Run a Free Instant Scan




Affected Software

Product  Packlink Pro Shipping
Category Wordpress Plugins
Vulnerable Domains291 live websites (100% of Packlink Pro Shipping install base)
Vulnerable Versions
  • from 0 through 3.4.6
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Nov 1, 2024
  • Updated - Nov 1, 2024

Credits

  • Dhabaleshwar Das (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2024-38740
United States15 websites



Spain86 websites
Italy72 websites
France52 websites
Germany36 websites
Belgium15 websites
Cyprus6 websites
GB6 websites
Denmark2 websites
Switzerland1 websites

Website Distribution by TLD

Number of websites using CVE-2024-38740
.com166 websites
.it41 websites
.es40 websites
.fr15 websites
.de5 websites
.eu5 websites
.net3 websites
.org3 websites
.co.uk2 websites

Websites affected by CVE-2024-38740

Top websites that are affected by CVE-2024-38740. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.com Spain***,***
****************.com Spain***,***
*******.com Italy*,***,***
*********************.com France*,***,***
**********.com Belgium*,***,***
********.********.com France*,***,***
**************.es Belgium*,***,***
****************.com United States*,***,***
****************.com Germany*,***,***
**********.com France*,***,***
See full domain list

FAQ

CVE-2024-38740 is Missing Authorization in Packlink Pro Shipping
A total of 291 websites have been identified as vulnerable to CVE-2024-38740, based on global website indexing conducted by WebTechSurvey.
The Packlink Pro Shipping is affected by the CVE-2024-38740 vulnerability.
Packlink Pro Shipping versions up to and including 3.4.6 are vulnerable to CVE-2024-38740.