Sensitive Data Exposure in Memberful Plugin for WordPress
CVE-2024-11294
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 17 December 2024
What is CVE-2024-11294?
CVE-2024-11294 represents a significant security vulnerability in the Memberful plugin for WordPress, affecting all versions up to and including 1.73.9. This vulnerability allows unauthenticated attackers to exploit the WordPress core search feature, leading to potential exposure of sensitive information from posts that are typically restricted to higher-level roles, such as site members. By exploiting this flaw, attackers can gain unauthorized access to sensitive data, posing a major risk to user privacy and data security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Memberful β Membership Plugin * <= 1.73.9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved