Sensitive Data Exposure in Memberful Plugin for WordPress
CVE-2024-11294
5.3MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 17 December 2024
Summary
CVE-2024-11294 represents a significant security vulnerability in the Memberful plugin for WordPress, affecting all versions up to and including 1.73.9. This vulnerability allows unauthenticated attackers to exploit the WordPress core search feature, leading to potential exposure of sensitive information from posts that are typically restricted to higher-level roles, such as site members. By exploiting this flaw, attackers can gain unauthorized access to sensitive data, posing a major risk to user privacy and data security.
Affected Version(s)
Memberful – Membership Plugin * <= 1.73.9
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Francesco Carlucci