github.comrelease notes
https://github.com/cloudflare/Cloudflare-WordPress/releases/tag/v4.12.3 CVE-2024-0212
HIGH
Cloudflare WordPress plugin enables information disclosure of Cloudflare API (for low privileged users)
Record summary
CVE-2024-0212 has a selected CVSS score of 8.1 (high).
Description
The Cloudflare Wordpress plugin was found to be vulnerable to improper authentication. The vulnerability enables attackers with a lower privileged account to access data from the Cloudflare API.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 7, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Cloudflare-WordPressBrowse Cloudflare / Cloudflare-WordPressDefault status: unaffected | CVE List | Through 4.12.2 | affected |
References
2github.comVendor advisory
https://github.com/cloudflare/Cloudflare-WordPress/security/advisories/GHSA-h2fj-7r3m-7gf2