CVE-2024-2107
CVSS 3.1 Score 9.1 of 10 (high)
Details
Published Mar 12, 2024
Updated: Mar 13, 2024
Summary
CVE-2024-2107 is a vulnerability affecting the Blossom Spa theme for WordPress. This issue, present in versions up to 1.3.4, allows unauthenticated attackers to extract sensitive data. The vulnerability stems from generated source code, which can be exploited to access contents of password-protected or scheduled posts. This exposure of sensitive information poses a significant security risk for WordPress sites using the Blossom Spa theme. It is recommended that users update to the latest theme version to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share