Anonymous Restricted Content Plugin Vulnerable to Information Disclosure
CVE-2024-0909
7.5HIGH
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 3 February 2024
Summary
The Anonymous Restricted Content plugin, utilized within WordPress, has been identified to possess an information disclosure vulnerability affecting all versions up to and including 1.6.2. The root cause lies in inadequate restrictions imposed through the REST API on the posts and pages that are designed to have protections. This flaw potentially enables unauthenticated attackers to exploit the vulnerability, leading to unauthorized access to sensitive content that should be protected.
Affected Version(s)
Anonymous Restricted Content * <= 1.6.2
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Francesco Carlucci