The ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.15.18 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as administrator.
Metrics
Affected Vendors & Products
References
History
Wed, 27 Nov 2024 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Profilepress
Profilepress loginwp |
|
CPEs | cpe:2.3:a:profilepress:loginwp:-:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Profilepress
Profilepress loginwp |
|
Metrics |
ssvc
|
Wed, 27 Nov 2024 05:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.15.18 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as administrator. | |
Title | ProfilePress <= 4.15.18 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-11-27T05:31:54.074Z
Updated: 2024-11-27T12:06:01.992Z
Reserved: 2024-11-11T18:52:00.429Z
Link: CVE-2024-11083
Vulnrichment
Updated: 2024-11-27T12:05:49.638Z
NVD
Status : Received
Published: 2024-11-27T06:15:17.707
Modified: 2024-11-27T06:15:17.707
Link: CVE-2024-11083
Redhat
No data.