CVE Vulnerabilities

CVE-2024-0969

Published: Feb 05, 2024 | Modified: Feb 13, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The ARMember plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugins Default Restriction feature and view restricted post content.

Affected Software

Name Vendor Start Version End Version
Armember Reputeinfosystems * 4.0.24 (including)

References