CVE-2024-13228: Qubely – Advanced Gutenberg Blocks <= 1.8.13 - Authenticated (Contributor+) Sensitive Information Exposure via qubely_get_content
The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.13 via the 'qubelygetcontent'. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, scheduled, password-protected, draft, and trashed post data.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13228?
CVE-2024-13228 is considered a medium severity vulnerability due to its potential for exposing sensitive information to authenticated attackers.
How do I fix CVE-2024-13228?
To fix CVE-2024-13228, update the Qubely – Advanced Gutenberg Blocks plugin to version 1.8.14 or higher.
Who is affected by CVE-2024-13228?
CVE-2024-13228 affects all users of the Qubely – Advanced Gutenberg Blocks plugin up to and including version 1.8.13.
What kind of exposure does CVE-2024-13228 cause?
CVE-2024-13228 allows authenticated users with Contributor-level access and above to expose sensitive information through the 'qubely_get_content' function.
Is CVE-2024-13228 easily exploitable?
Yes, CVE-2024-13228 is easily exploitable by authenticated attackers due to its reliance on low-level access permissions.