Information Exposure Vulnerability in s2Member Plugin for WordPress
CVE-2024-0899
5.3MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 9 April 2024
Summary
The s2Member plugin for WordPress, essential for managing memberships and content access, is exposed to a significant vulnerability. All versions up to and including 230815 allow unauthenticated attackers to access sensitive post and page content through the API. This flaw compromises user privacy and data security, enabling unauthorized views of otherwise restricted content.
Affected Version(s)
s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions * <= 230815
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Francesco Carlucci