CVE-2024-10688
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2024-10688 is a newly disclosed Information Exposure vulnerability affecting the Attesa Extra plugin for WordPress. This issue, present in all versions up to 1.4.2, permits authenticated attackers with Contributor-level access or higher to obtain data from password-protected, private, or draft posts. The 'attesa-template' shortcode is the root cause, as it fails to adequately restrict which posts can be accessed. Consequently, sensitive information can be exposed to unintended parties. It is highly recommended that WordPress users update the Attesa Extra plugin to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.