CVE-2024-12560: Button Block – Get fully customizable & multi-functional buttons <= 1.1.5 - Authenticated (Contributor+) Post Disclosure via Post Duplication
The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.5 via the 'btnblockduplicatepost' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract potentially sensitive data from draft, scheduled (future), private, and password protected posts.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12560?
CVE-2024-12560 is classified as a medium-severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2024-12560?
To mitigate CVE-2024-12560, update the Button Block plugin for WordPress to version 1.1.6 or later.
What systems are affected by CVE-2024-12560?
CVE-2024-12560 affects all versions of the Button Block plugin for WordPress up to and including version 1.1.5.
Who can exploit CVE-2024-12560?
CVE-2024-12560 can be exploited by authenticated attackers who have access to the WordPress site.
What does CVE-2024-12560 allow an attacker to do?
CVE-2024-12560 allows an attacker to expose sensitive information through the 'btn_block_duplicate_post' function.