PT-2024-37217 · WordPress · Hide My Site

Colin Xu

·

Published

2024-08-20

·

Updated

2024-08-21

·

CVE-2024-5880

CVSS v3.1

4.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Hide My Site plugin for WordPress versions up to, and including, 2.2
Description: The issue allows unauthenticated attackers to gain unauthorized access to the site due to the plugin not restricting access to the REST API when password protection is enabled. This makes it possible for attackers to expose sensitive information.
Recommendations: For versions up to, and including, 2.2, consider disabling the REST API access when password protection is enabled until a patch is available. Restrict access to the site to minimize the risk of exploitation.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-5880

Affected Products

Hide My Site