nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-11090 CVE-2024-11090
MEDIUM
Membership Plugin – Restrict Content <= 3.2.13 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure
Record summary
CVE-2024-11090 has a selected CVSS score of 5.3 (medium).
Description
The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.13 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as administrator.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 27, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Membership Plugin – Restrict ContentBrowse stellarwp / Membership Plugin – Restrict ContentDefault status: unaffected | CVE List | Through 3.2.13 | affected |
References
3plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/3227065/restrict-content wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/7615c391-ccb1-4990-bbfd-949782cc609a?source=cve