PT-2024-30400 · WordPress · Taxopress Wordpress Tag Cloud Plugin

Peng Zhou

·

Published

2024-09-25

·

Updated

2024-09-26

·

CVE-2024-43237

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions TaxoPress WordPress Tag Cloud Plugin – Tag Groups versions through 2.0.3
Description The issue is related to the exposure of sensitive information to an unauthorized actor. This affects the TaxoPress WordPress Tag Cloud Plugin, specifically the Tag Groups component. There is no information provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For versions through 2.0.3, upgrade to a version higher than 2.0.3 to mitigate the risk. Review logs for signs of exploitation. As a temporary workaround, consider restricting access to sensitive information until a patch is available.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-43237

Affected Products

Taxopress Wordpress Tag Cloud Plugin