Sensitive Data Exposure in Memberful Plugin for WordPress
CVE-2024-11294

5.3MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
17 December 2024

Summary

CVE-2024-11294 represents a significant security vulnerability in the Memberful plugin for WordPress, affecting all versions up to and including 1.73.9. This vulnerability allows unauthenticated attackers to exploit the WordPress core search feature, leading to potential exposure of sensitive information from posts that are typically restricted to higher-level roles, such as site members. By exploiting this flaw, attackers can gain unauthorized access to sensitive data, posing a major risk to user privacy and data security.

Affected Version(s)

Memberful – Membership Plugin * <= 1.73.9

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Francesco Carlucci
.