PT-2025-8667 · WordPress · Suremembers

Francesco Carlucci

·

Published

2025-02-26

·

Updated

2025-02-26

·

CVE-2024-12434

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SureMembers plugin for WordPress versions up to and including 1.10.6
Description The issue allows unauthenticated attackers to extract sensitive data, including restricted content, via the REST API.
Recommendations For versions up to and including 1.10.6, update to a version that contains a fix for this issue to prevent sensitive information exposure.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-12434

Affected Products

Suremembers