CVE-2024-0437
Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease <= 2.6.6 - Missing Authorization to Sensitive Information Exposure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.6 via the API. This makes it possible for authenticated attackers, with subscriber access or higher, to extract post titles and content, thus bypassing the plugin's password protection.
El complemento Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease de WordPress con facilidad es vulnerable a la exposición de información confidencial en todas las versiones hasta la 2.6.6 incluida a través de la API. Esto hace posible que atacantes autenticados, con acceso de suscriptor o superior, extraigan títulos y contenido de publicaciones, evitando así la protección con contraseña del complemento.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-01-11 CVE Reserved
- 2024-05-14 CVE Published
- 2024-05-15 EPSS Updated
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
CAPEC
References (2)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wpexpertsio Search vendor "Wpexpertsio" | Password Protected – Ultimate Plugin To Password Protect Your WordPress Content With Ease Search vendor "Wpexpertsio" for product "Password Protected – Ultimate Plugin To Password Protect Your WordPress Content With Ease" | <= 2.6.6 Search vendor "Wpexpertsio" for product "Password Protected – Ultimate Plugin To Password Protect Your WordPress Content With Ease" and version " <= 2.6.6" | en |
Affected
|