CVE-2024-0212: Cloudflare WordPress plugin enables information disclosure of Cloudflare API (for low privileged users)
Published Jan 29, 2024
·Updated
The Cloudflare Wordpress plugin was found to be vulnerable to improper authentication. The vulnerability enables attackers with a lower privileged account to access data from the Cloudflare API.
Affected Software
1 affected component
Cloudflare Cloudflare Wordpress<4.12.3
Event History
Jan 29, 2024
CVE Published
via MITRE·09:13 AM
Data Sourced
via MITRE·09:13 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-0212?
CVE-2024-0212 has been rated as a high severity vulnerability due to improper authentication allowing unauthorized access.
2
How do I fix CVE-2024-0212?
To fix CVE-2024-0212, update the Cloudflare WordPress plugin to version 4.12.3 or later.
3
Who is affected by CVE-2024-0212?
CVE-2024-0212 affects users of the Cloudflare WordPress plugin versions prior to 4.12.3.
4
What type of vulnerability is CVE-2024-0212?
CVE-2024-0212 is classified as an improper authentication vulnerability.
5
Can CVE-2024-0212 lead to data exposure?
Yes, CVE-2024-0212 can allow attackers with lower privileges to access sensitive data from the Cloudflare API.