PT-2024-38867 · WordPress · Permalink Manager Lite

Matthew Rollings

+1

·

Published

2024-08-28

·

Updated

2024-09-13

·

CVE-2024-8195

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Permalink Manager Lite plugin for WordPress versions up to, and including, 2.4.4
Description: The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the debug data, debug query, and debug redirect functions. This makes it possible for unauthenticated attackers to extract sensitive data including password, title, and content of password-protected posts.
Recommendations: For versions up to, and including, 2.4.4, consider disabling the debug data, debug query, and debug redirect functions until a patch is available to prevent unauthorized access to sensitive data. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-8195

Affected Products

Permalink Manager Lite