CVE-2024-10796: If-So Dynamic Content Personalization <= 1.9.2.1 - Authenticated (Contributor+) Post Disclosure
The If-So Dynamic Content Personalization plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.2.1 via the 'ifso-show-post' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts created via Elementor that they should not have access to.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10796?
CVE-2024-10796 is classified as a medium severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2024-10796?
To mitigate the vulnerability CVE-2024-10796, update the If-So Dynamic Content Personalization plugin to version 1.9.2.2 or later.
What type of vulnerability is CVE-2024-10796?
CVE-2024-10796 is an Information Exposure vulnerability.
Who is affected by CVE-2024-10796?
The vulnerability CVE-2024-10796 affects all installations of the If-So Dynamic Content Personalization plugin for WordPress versions up to and including 1.9.2.1.
What is the attack vector for CVE-2024-10796?
CVE-2024-10796 can be exploited via the 'ifso-show-post' shortcode due to insufficient restrictions on included posts.