CVE-2024-1435: WordPress Tainacan plugin <= 0.20.6 - Sensitive Data Exposure via Log File vulnerability
Published Feb 29, 2024
·Updated
Insertion of Sensitive Information Into Sent Data vulnerability in tainacan Tainacan tainacan.This issue affects Tainacan: from n/a through <= 0.20.6.
Affected Software
3 affected components
Tainacan Tainacan Wordpress<0.20.7
Tainacan.Org Tainacan<=0.20.6
WordPress Tainacan plugin<=0.20.6
Event History
Feb 29, 2024
CVE Published
via MITRE·05:03 AM
Data Sourced
via MITRE·05:03 AM
DescriptionWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-1435?
CVE-2024-1435 is classified as a medium severity vulnerability.
2
How do I fix CVE-2024-1435?
To fix CVE-2024-1435, upgrade Tainacan to version 0.20.7 or later.
3
What kind of information is exposed in CVE-2024-1435?
CVE-2024-1435 can expose sensitive information to unauthorized actors through log files.
4
Which versions of Tainacan are affected by CVE-2024-1435?
CVE-2024-1435 affects Tainacan versions up to and including 0.20.6.
5
Is the WordPress Tainacan Plugin vulnerable to CVE-2024-1435?
Yes, the WordPress Tainacan Plugin up to version 0.20.6 is also vulnerable to CVE-2024-1435.