WordPress · Publishpress Revisions · CVE-2024-11154
**Name of the Vulnerable Software and Affected Versions**
PublishPress Revisions plugin versions up to, and including, 3.5.15
**Description**
The issue allows authenticated attackers with Subscriber-level access and above to extract sensitive data, including revisions of posts and pages, via the `actAjaxRevisionDiffs` function.
**Recommendations**
For versions up to, and including, 3.5.15, update to a version higher than 3.5.15 to resolve the issue.
As a temporary workaround, consider restricting access to the `actAjaxRevisionDiffs` function until a patch is available.