Vulnerability Description
The Restrict User Access – Ultimate Membership & Content Protection plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5 via API. This makes it possible for unauthenticated attackers to obtain the contents of posts and pages via API.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dev.Institute | Restrict User Access | < 2.6 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&newPatch
- https://www.wordfence.com/threat-intel/vulnerabilities/id/f67684cd-3e0f-48bb-967Third Party Advisory
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&newPatch
- https://www.wordfence.com/threat-intel/vulnerabilities/id/f67684cd-3e0f-48bb-967Third Party Advisory
FAQ
What is CVE-2024-0687?
CVE-2024-0687 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The Restrict User Access – Ultimate Membership & Content Protection plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5 via API. This makes it possible...
How severe is CVE-2024-0687?
CVE-2024-0687 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-0687?
Check the references section above for vendor advisories and patch information. Affected products include: Dev.Institute Restrict User Access.