CVE-2024-11294: Memberful <= 1.73.9 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure
The Memberful plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.73.9 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as site members.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11294?
CVE-2024-11294 has been classified with a medium severity due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2024-11294?
To fix CVE-2024-11294, update the Memberful plugin to version 1.74 or later as soon as possible.
What versions of the Memberful plugin are affected by CVE-2024-11294?
All versions of the Memberful plugin up to and including 1.73.9 are affected by CVE-2024-11294.
What type of vulnerability is CVE-2024-11294?
CVE-2024-11294 is categorized as a Sensitive Information Exposure vulnerability.
Can unauthenticated users exploit CVE-2024-11294?
Yes, unauthenticated attackers can exploit CVE-2024-11294 to access restricted sensitive data.