CVE-2024-7870

MEDIUM

PixelYourSite < 9.7.2 and < 10.4.3 - Unauthenticated Sensitive Information Exposure via Public Log Files

Title source: llm
STIX 2.1

Description

The PixelYourSite – Your smart PIXEL (TAG) & API Manager and the PixelYourSite PRO plugins for WordPress are vulnerable to Sensitive Information Exposure in all versions up to, and including, 9.7.1 and 10.4.2, respectively, through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files, and to delete log files.

Scores

CVSS v3 6.5
EPSS 0.0045
EPSS Percentile 35.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (4)
pixelyoursite/pixelyoursite < 10.4.3
pixelyoursite/pixelyoursite < 9.7.2
pixelyoursite/PixelYourSite Pro – Your smart PIXEL (TAG) Manager < 10.4.2
pixelyoursite/PixelYourSite – Your smart PIXEL (TAG) & API Manager < 9.7.1
Published Sep 04, 2024
Tracked Since Feb 18, 2026