The FULL - Customer plugin for WordPress is vulnerable to Information Disclosure via the /health REST route in versions up to, and including, 2.2.3 due to improper authorization. This allows authenticated attackers with subscriber-level permissions and above to obtain sensitive information about the site configuration as disclosed by the WordPress health check.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 05 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-02-05T19:36:52.211Z

Reserved: 2023-08-08T15:28:19.695Z

Link: CVE-2023-4242

cve-icon Vulnrichment

Updated: 2024-08-02T07:24:03.560Z

cve-icon NVD

Status : Modified

Published: 2023-08-09T04:15:10.657

Modified: 2024-11-21T08:34:41.870

Link: CVE-2023-4242

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.