CVE-2024-30233: WordPress WholesaleX plugin <= 1.3.1 - Sensitive Data Exposure on User Export vulnerability
Published Mar 26, 2024
·Updated
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.1.
Affected Software
3 affected components
Wholesale WholesaleX<=1.3.1
WordPress WholesaleX plugin<=1.3.1
wpxpo Wholesalex Wordpress<1.3.2
Remediation
Information
Update to 1.3.2 or a higher version.
Event History
Mar 26, 2024
CVE Published
via MITRE·12:10 PM
Data Sourced
via MITRE·12:10 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-30233?
CVE-2024-30233 has a medium severity rating due to the exposure of sensitive information to unauthorized actors.
2
How do I fix CVE-2024-30233?
To fix CVE-2024-30233, upgrade WholesaleX or the WholesaleX plugin to version 1.3.2 or later.
3
What type of vulnerability is CVE-2024-30233?
CVE-2024-30233 is classified as an Exposure of Sensitive Information to an Unauthorized Actor vulnerability.
4
Which versions of WholesaleX are affected by CVE-2024-30233?
CVE-2024-30233 affects WholesaleX versions up to and including 1.3.1.
5
Can CVE-2024-30233 affect WordPress installations?
Yes, CVE-2024-30233 also affects the WholesaleX plugin for WordPress up to version 1.3.1.