Vulnerability Description
The Swift Performance Lite WordPress plugin before 2.3.6.15 does not prevent users from exporting the plugin's settings, which may include sensitive information such as Cloudflare API tokens.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Swteplugins | Swift Performance | < 2.3.6.15 |
References
- https://wpscan.com/vulnerability/8c83dd57-9291-4dfc-846d-5ad47534e2adExploitThird Party Advisory
- https://wpscan.com/vulnerability/8c83dd57-9291-4dfc-846d-5ad47534e2adExploitThird Party Advisory
FAQ
What is CVE-2023-6289?
CVE-2023-6289 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The Swift Performance Lite WordPress plugin before 2.3.6.15 does not prevent users from exporting the plugin's settings, which may include sensitive information such as Cloudflare API tokens.
How severe is CVE-2023-6289?
CVE-2023-6289 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-6289?
Check the references section above for vendor advisories and patch information. Affected products include: Swteplugins Swift Performance.