PT-2024-27169 · WordPress · Wp Staging Pro+1

Haidv35

·

Published

2024-04-26

·

Updated

2024-04-26

·

CVE-2024-3682

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WP STAGING versions up to 3.4.3 WP STAGING Pro versions up to 5.4.3
Description The issue allows unauthenticated attackers to extract sensitive data from a log file, including system information and license keys, via the ajaxSendReport function. This is possible when an administrator has used the 'Contact Us' functionality along with the option to automatically submit log files.
Recommendations For WP STAGING versions up to 3.4.3, update to a version later than 3.4.3 to resolve the issue. For WP STAGING Pro versions up to 5.4.3, update to a version later than 5.4.3 to resolve the issue. As a temporary workaround, consider disabling the ajaxSendReport function until a patch is available.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-3682

Affected Products

Wp Staging
Wp Staging Pro