TROYANOSYVIRUS
Voltar para CVEs

CVE-2024-11088

MEDIUM
5.3

Descricao

The Simple Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.5 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as administrator.

Detalhes CVE

Pontuacao CVSS v3.15.3
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado11/21/2024
Ultima modificacao4/5/2025
Fontenvd
Avistamentos honeypot0

Produtos afetados

simple-membership-plugin:simple_membership

Fraquezas (CWE)

CWE-200CWE-276

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.