Sensitive Data Exposure in Memberful Plugin for WordPress
CVE-2024-11294
5.3MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 17 December 2024
What is CVE-2024-11294?
CVE-2024-11294 represents a significant security vulnerability in the Memberful plugin for WordPress, affecting all versions up to and including 1.73.9. This vulnerability allows unauthenticated attackers to exploit the WordPress core search feature, leading to potential exposure of sensitive information from posts that are typically restricted to higher-level roles, such as site members. By exploiting this flaw, attackers can gain unauthorized access to sensitive data, posing a major risk to user privacy and data security.
Affected Version(s)
Memberful – Membership Plugin * <= 1.73.9