The Host PHP Info plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to read configuration settings and predefined variables on the site's server. The plugin does not need to be activated for the vulnerability to be exploited.
Metrics
Affected Vendors & Products
References
History
Tue, 07 Jan 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 07 Jan 2025 05:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Host PHP Info plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to read configuration settings and predefined variables on the site's server. The plugin does not need to be activated for the vulnerability to be exploited. | |
Title | Host PHP Info <= 1.0.4 - Missing Authorization to Unauthenticated Sensitive Information Disclosure | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-01-07T05:23:55.768Z
Updated: 2025-01-07T16:15:35.715Z
Reserved: 2024-12-11T18:10:39.662Z
Link: CVE-2024-12535
Vulnrichment
Updated: 2025-01-07T15:55:36.924Z
NVD
Status : Received
Published: 2025-01-07T06:15:17.220
Modified: 2025-01-07T06:15:17.220
Link: CVE-2024-12535
Redhat
No data.