The SureMembers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.10.6 via the REST API. This makes it possible for unauthenticated attackers to extract sensitive data including restricted content.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Mar 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 26 Feb 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The SureMembers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.10.6 via the REST API. This makes it possible for unauthenticated attackers to extract sensitive data including restricted content. | |
Title | SureMembers <= 1.10.6 - Sensitive Information Exposure | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-02-26T03:27:22.029Z
Updated: 2025-02-26T15:34:27.912Z
Reserved: 2024-12-10T17:48:54.549Z
Link: CVE-2024-12434

Updated: 2025-02-26T14:50:14.857Z

Status : Received
Published: 2025-02-26T13:15:36.353
Modified: 2025-02-26T13:15:36.353
Link: CVE-2024-12434

No data.