Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wp2speed WP2Speed Faster allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP2Speed Faster: from n/a through 1.0.1.
History

Tue, 13 Aug 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Wp2speed
Wp2speed wp2speed
CPEs cpe:2.3:a:wp2speed:wp2speed:*:*:*:*:*:*:*:*
Vendors & Products Wp2speed
Wp2speed wp2speed
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 12 Aug 2024 23:15:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wp2speed WP2Speed Faster allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP2Speed Faster: from n/a through 1.0.1.
Title WordPress WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 plugin <= 1.0.1 - Sensitive Data Exposure vulnerability
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published: 2024-08-12T22:56:42.982Z

Updated: 2024-08-13T16:04:09.633Z

Reserved: 2024-06-10T21:13:51.398Z

Link: CVE-2024-37924

cve-icon Vulnrichment

Updated: 2024-08-13T16:03:51.376Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-12T23:15:15.703

Modified: 2024-08-13T12:58:25.437

Link: CVE-2024-37924

cve-icon Redhat

No data.