CVE-2024-0212
Cloudflare WordPress plugin enables information disclosure of Cloudflare API (for low privileged users)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Cloudflare Wordpress plugin was found to be vulnerable to improper authentication. The vulnerability enables attackers with a lower privileged account to access data from the Cloudflare API.
Se descubrió que el complemento Cloudflare Wordpress era vulnerable a una autenticación incorrecta. La vulnerabilidad permite a los atacantes con una cuenta con menos privilegios acceder a datos de la API de Cloudflare.
The Cloudflare plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'initProxy' function in versions up to and including 4.12.2. This makes it possible for authenticated attackers, with subscriber access and above, to send requests proxied through Cloudflare to arbitrary URLs.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2024-01-03 CVE Reserved
- 2024-01-04 CVE Published
- 2024-02-02 EPSS Updated
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
- CWE-862: Missing Authorization
CAPEC
- CAPEC-54: Query System for Information
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/cloudflare/Cloudflare-WordPress/releases/tag/v4.12.3 | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/cloudflare/Cloudflare-WordPress/security/advisories/GHSA-h2fj-7r3m-7gf2 | 2024-02-02 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cloudflare Search vendor "Cloudflare" | Cloudflare Search vendor "Cloudflare" for product "Cloudflare" | < 4.12.3 Search vendor "Cloudflare" for product "Cloudflare" and version " < 4.12.3" | wordpress |
Affected
|