PT-2025-8667 · WordPress · Suremembers

Francesco Carlucci

·

Publicado

2025-02-26

·

Atualizado

2025-02-26

·

CVE-2024-12434

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SureMembers plugin for WordPress versions up to and including 1.10.6
Description The issue allows unauthenticated attackers to extract sensitive data, including restricted content, via the REST API.
Recommendations For versions up to and including 1.10.6, update to a version that contains a fix for this issue to prevent sensitive information exposure.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2024-12434

Produtos afetados

Suremembers