Sensitive Information Exposure Vulnerability in Button Block Plugin for WordPress
CVE-2024-12560
6.5MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 19 December 2024
What is CVE-2024-12560?
CVE-2024-12560 represents a significant security vulnerability in the Button Block – a popular customizable button plugin for WordPress. This vulnerability allows authenticated attackers, specifically those with Contributor-level access and higher, to exploit the 'btn_block_duplicate_post' function. It enables them to extract potentially sensitive data from draft, scheduled, private, and password-protected posts. As such, it poses a serious risk for website security and data integrity, emphasizing the need for immediate updates to safeguard against unauthorized data retrieval.
Affected Version(s)
Button Block – Get fully customizable & multi-functional buttons * <= 1.1.5