CVE-2024-12294: Last Viewed Posts by WPBeginner <= 1.0.1 - Unauthenticated Sensitive Information Exposure
The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.1 via the 'getlegacycookies' function. This makes it possible for unauthenticated attackers to extract sensitive data including titles and permalinks of private, password-protected, pending, and draft posts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12294?
CVE-2024-12294 is considered a high severity vulnerability due to the potential for sensitive information exposure.
How do I fix CVE-2024-12294?
To fix CVE-2024-12294, update the Last Viewed Posts plugin to version 1.0.2 or later.
What software is affected by CVE-2024-12294?
CVE-2024-12294 affects the Last Viewed Posts plugin by WPBeginner in all versions up to and including 1.0.1.
What kind of data could be exposed due to CVE-2024-12294?
CVE-2024-12294 could allow attackers to extract sensitive data, including post titles and other private information.
Who can exploit CVE-2024-12294?
CVE-2024-12294 can be exploited by unauthenticated attackers, making it particularly dangerous.