PT-2024-18829 · WordPress · Booster Extension

Krzysztof Zając

·

Published

2024-05-02

·

Updated

2024-05-02

·

CVE-2024-2109

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Booster Extension plugin for WordPress version 1.2.0 and earlier
Description The issue allows unauthenticated attackers to extract sensitive data, including user emails, via the booster extension authorbox shortcode display function.
Recommendations For Booster Extension plugin for WordPress version 1.2.0 and earlier, update to a version later than 1.2.0 to resolve the issue. As a temporary workaround, consider disabling the booster extension authorbox shortcode display function until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-2109

Affected Products

Booster Extension