CVE-2024-12560
Button Block – Get fully customizable & multi-functional buttons <= 1.1.5 - Authenticated (Contributor+) Post Disclosure via Post Duplication
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.5 via the 'btn_block_duplicate_post' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract potentially sensitive data from draft, scheduled (future), private, and password protected posts.
El complemento Button Block – Get fully customizable & multi-function button-buttons para WordPress es vulnerable a la exposición de información confidencial en todas las versiones hasta la 1.1.5 incluida a través de la función 'btn_block_duplicate_post'. Esto permite que atacantes autenticados, con acceso de nivel de colaborador y superior, extraigan datos potencialmente confidenciales de publicaciones en borrador, programadas (futuras), privadas y protegidas con contraseña.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-12-12 CVE Reserved
- 2024-12-18 CVE Published
- 2024-12-19 CVE Updated
- 2024-12-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://plugins.trac.wordpress.org/changeset/3208482/button-block | ||
https://www.wordfence.com/threat-intel/vulnerabilities/id/ac55e988-2b41-459b-9ab1-e5f9fdca203f?source=cve |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Bplugins Search vendor "Bplugins" | Button Block – Get Fully Customizable & Multi-functional Buttons Search vendor "Bplugins" for product "Button Block – Get Fully Customizable & Multi-functional Buttons" | <= 1.1.5 Search vendor "Bplugins" for product "Button Block – Get Fully Customizable & Multi-functional Buttons" and version " <= 1.1.5" | en |
Affected
|