The SureMembers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.10.6 via the REST API. This makes it possible for unauthenticated attackers to extract sensitive data including restricted content.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Feb 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SureMembers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.10.6 via the REST API. This makes it possible for unauthenticated attackers to extract sensitive data including restricted content. | |
| Title | SureMembers <= 1.10.6 - Sensitive Information Exposure | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-02-26T03:27:22.029Z
Updated: 2025-02-26T15:34:27.912Z
Reserved: 2024-12-10T17:48:54.549Z
Link: CVE-2024-12434
Updated: 2025-02-26T14:50:14.857Z
Status : Received
Published: 2025-02-26T13:15:36.353
Modified: 2025-02-26T13:15:36.353
Link: CVE-2024-12434
No data.