PT-2024-37217 · WordPress · Hide My Site
Colin Xu
·
Published
2024-08-20
·
Updated
2024-08-21
·
CVE-2024-5880
CVSS v3.1
4.3
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Hide My Site plugin for WordPress versions up to, and including, 2.2
Description:
The issue allows unauthenticated attackers to gain unauthorized access to the site due to the plugin not restricting access to the REST API when password protection is enabled. This makes it possible for attackers to expose sensitive information.
Recommendations:
For versions up to, and including, 2.2, consider disabling the REST API access when password protection is enabled until a patch is available. Restrict access to the site to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hide My Site