The f(x) Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.1 via the API. This makes it possible for unauthenticated attackers to obtain page and post contents of a site protected with this plugin.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Mar 2025 01:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Shellcreeper
Shellcreeper f\(x\) Private Site |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:shellcreeper:f\(x\)_private_site:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Shellcreeper
Shellcreeper f\(x\) Private Site |

Status: PUBLISHED
Assigner: Wordfence
Published: 2024-03-12T08:34:17.481Z
Updated: 2024-08-01T18:18:19.079Z
Reserved: 2024-01-25T20:05:55.951Z
Link: CVE-2024-0906

Updated: 2024-08-01T18:18:19.079Z

Status : Analyzed
Published: 2024-03-12T09:15:06.670
Modified: 2025-03-13T01:22:21.293
Link: CVE-2024-0906

No data.