Unauthorized Access to Sensitive Information
CVE-2024-43258

7.5HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
26 August 2024

Summary

The vulnerability pertains to the Store Locator Plus plugin, where sensitive information can be exposed to unauthorized actors. This issue impacts versions of the plugin from its initial release through 2311.17.01, raising significant concerns around the security of user data. Proper access controls are essential to prevent unauthorized access and ensure data integrity within applications utilizing this plugin. Implementing security measures is critical to safeguarding sensitive user information against potential breaches.

Affected Version(s)

Store Locator Plus <= 2311.17.01

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

Credit

Peng Zhou (Patchstack Alliance)
.