Anonymous Restricted Content Plugin Vulnerable to Information Disclosure
CVE-2024-0909

7.5HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
3 February 2024

Summary

The Anonymous Restricted Content plugin, utilized within WordPress, has been identified to possess an information disclosure vulnerability affecting all versions up to and including 1.6.2. The root cause lies in inadequate restrictions imposed through the REST API on the posts and pages that are designed to have protections. This flaw potentially enables unauthenticated attackers to exploit the vulnerability, leading to unauthorized access to sensitive content that should be protected.

Affected Version(s)

Anonymous Restricted Content * <= 1.6.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Francesco Carlucci
.