Sensitive Information Exposure Vulnerability in Button Block Plugin for WordPress
CVE-2024-12560
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 19 December 2024
What is CVE-2024-12560?
CVE-2024-12560 represents a significant security vulnerability in the Button Block β a popular customizable button plugin for WordPress. This vulnerability allows authenticated attackers, specifically those with Contributor-level access and higher, to exploit the 'btn_block_duplicate_post' function. It enables them to extract potentially sensitive data from draft, scheduled, private, and password-protected posts. As such, it poses a serious risk for website security and data integrity, emphasizing the need for immediate updates to safeguard against unauthorized data retrieval.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Button Block β Get fully customizable & multi-functional buttons * <= 1.1.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved