The Opal Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.4 via the private notes functionality on payments which utilizes WordPress comments. This makes it possible for authenticated attackers, with subscriber-level access and above, to view private notes via recent comments that should be restricted to just administrators.
Metrics
Affected Vendors & Products
References
History
Mon, 12 Aug 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 10 Aug 2024 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Opal Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.4 via the private notes functionality on payments which utilizes WordPress comments. This makes it possible for authenticated attackers, with subscriber-level access and above, to view private notes via recent comments that should be restricted to just administrators. | |
Title | Opal Membership <= 1.2.4 - Authenticated (Subscriber+) Information Disclosure | |
Weaknesses | CWE-862 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-08-10T03:23:26.394Z
Updated: 2024-08-12T14:31:45.025Z
Reserved: 2024-08-09T14:57:49.314Z
Link: CVE-2024-7648
Vulnrichment
Updated: 2024-08-12T14:31:41.135Z
NVD
Status : Awaiting Analysis
Published: 2024-08-12T13:38:48.890
Modified: 2024-08-12T13:41:36.517
Link: CVE-2024-7648
Redhat
No data.