CVE-2024-2950: BoldGrid Easy SEO – Simple and Effective SEO <= 1.6.14 - Information Exposure
Published Apr 6, 2024
·Updated
The BoldGrid Easy SEO – Simple and Effective SEO plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.6.14 via meta information (og:description) This makes it possible for unauthenticated attackers to view the first 130 characters of a password protected post which can contain sensitive information.
Affected Software
2 affected components
BoldGrid Easy SEO<=1.6.14
BoldGrid Easy Seo Wordpress<1.6.15
Event History
Apr 6, 2024
CVE Published
via MITRE·03:24 AM
Data Sourced
via MITRE·03:24 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-2950?
CVE-2024-2950 is considered a medium severity vulnerability due to information exposure risks.
2
How do I fix CVE-2024-2950?
To fix CVE-2024-2950, update the BoldGrid Easy SEO plugin to version 1.6.15 or later.
3
What versions are affected by CVE-2024-2950?
CVE-2024-2950 affects all versions of BoldGrid Easy SEO up to and including 1.6.14.
4
What type of vulnerability is CVE-2024-2950?
CVE-2024-2950 is classified as an Information Exposure vulnerability.
5
Who can exploit CVE-2024-2950?
CVE-2024-2950 can be exploited by unauthenticated attackers.