CVE-2024-11090

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 26, 2025
Updated: Feb 4, 2025
CWE ID 200

Summary

CVE-2024-11090 refers to a vulnerability in the Membership Plugin – Restrict Content for WordPress. This issue allows unauthenticated attackers to extract sensitive information from restricted posts through the WordPress core search feature, affecting all versions up to 3.2.13. The vulnerability exposes data meant for higher-level roles, such as administrators, increasing the risk of confidentiality breaches. Users are advised to upgrade to the latest plugin version to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share