CVE-2024-30514
WordPress Paid Memberships Pro – Payfast Gateway Add On plugin <= 1.4.1 - Sensitive Data Exposure via Log File vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Insertion of Sensitive Information into Log File vulnerability in Paid Memberships Pro Paid Memberships Pro – Payfast Gateway Add On.This issue affects Paid Memberships Pro – Payfast Gateway Add On: from n/a through 1.4.1.
Vulnerabilidad de inserción de información confidencial en el archivo de registro en Paid Memberships Pro Paid Memberships Pro – Payfast Gateway Add On. Este problema afecta a Paid Memberships Pro – Payfast Gateway Add On: desde n/a hasta 1.4.1.
The Paid Memberships Pro – Payfast Gateway Add On plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.1 via log files. This makes it possible for unauthenticated attackers to extract potentially sensitive information from log files.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-03-27 CVE Reserved
- 2024-03-28 CVE Published
- 2024-03-30 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-532: Insertion of Sensitive Information into Log File
CAPEC
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pmpro Payfast Search vendor "Pmpro Payfast" | Pmpro Payfast Search vendor "Pmpro Payfast" for product "Pmpro Payfast" | >= 0.0.0 <= 1.4.1 Search vendor "Pmpro Payfast" for product "Pmpro Payfast" and version " >= 0.0.0 <= 1.4.1" | en |
Affected
|