ZeroHour

CVE-2024-0906

CVSS 3.1
5.3 medium
EPSS
<1%p39
Published
()
Modified
Description

The f(x) Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.1 via the API. This makes it possible for unauthenticated attackers to obtain page and post contents of a site protected with this plugin.

Vendors
shellcreeper
Products
f\(x\) private site
Ecosystems
WordPress
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.