Sensitive Information Exposure in Member Access Plugin for WordPress
CVE-2024-11290
5.3MEDIUM
What is CVE-2024-11290?
The Member Access plugin for WordPress has a vulnerability that exposes sensitive information through the WordPress core search feature. This flaw allows unauthenticated attackers to gather confidential data from posts intended for higher-level user roles, such as administrators. By exploiting this vulnerability, attackers can bypass access controls, potentially leading to unauthorized data disclosure.
Affected Version(s)
Member Access * <= 1.1.6