CVE-2024-11282: Passster – Password Protect Pages and Content <= 4.2.10 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure
The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.10 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as administrator.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11282?
CVE-2024-11282 has been classified as a high-severity vulnerability due to its potential for sensitive information exposure.
How do I fix CVE-2024-11282?
To fix CVE-2024-11282, update the Passster – Password Protect Pages and Content plugin to version 4.2.11 or later.
Who is affected by CVE-2024-11282?
All users of the Passster – Password Protect Pages and Content plugin for WordPress up to version 4.2.10 are affected by CVE-2024-11282.
What kind of data is exposed in CVE-2024-11282?
CVE-2024-11282 could allow unauthenticated attackers to access sensitive data through the WordPress core search feature.
Is there a workaround for CVE-2024-11282?
There are no recommended workarounds for CVE-2024-11282; updating the plugin is the only effective solution.