VYPR
Medium severity5.3NVD Advisory· Published Jun 11, 2024· Updated Apr 15, 2026

CVE-2024-34768

CVE-2024-34768

Description

Missing Authorization vulnerability in Fastly.This issue affects Fastly: from n/a through 1.2.25.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The Fastly WordPress plugin through version 1.2.25 contains a broken access control vulnerability allowing unauthenticated privilege escalation.

The Fastly WordPress plugin (versions up to 1.2.25) suffers from a missing authorization vulnerability [1]. This broken access control issue means that the plugin fails to properly verify permissions or nonce tokens in certain functions, enabling unprivileged users to execute actions normally reserved for higher-privileged roles.

Attackers can exploit this vulnerability remotely without authentication [1]. The lack of proper capability checks allows an unauthenticated attacker to perform administrative actions, bypassing the intended access restrictions. This type of vulnerability is frequently targeted in mass-exploit campaigns against WordPress sites [1].

The impact is privilege escalation, where an attacker can gain unauthorized administrative control over the affected WordPress installation [1]. While the CVSS score is 5.3 (Medium), the practical risk is elevated due to the ease of exploitation and the plugin's widespread use.

Patchstack has assigned a low severity impact but recommends immediate action [1]. The vulnerability is fixed in version 1.2.26 of the Fastly plugin [1]. Users are advised to update immediately or enable auto-updates for vulnerable plugins. Site owners unable to update should consult their hosting provider or web developer for assistance [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.