CVE-2024-37110: WordPress WishList Member X plugin < 3.26.7 - Unauthenticated Settings & Users Data Dump vulnerability
Published Jul 10, 2024
·Updated
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7.
Affected Software
2 affected components
WishList WishList Member X<3.26.7
WordPress WishList Member X<3.26.7
Remediation
Information
Update to 3.26.7 or a higher version.
Event History
Jul 10, 2024
CVE Published
via MITRE·05:58 PM
Data Sourced
via MITRE·05:58 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-37110?
CVE-2024-37110 is classified as a vulnerability that allows unauthorized exposure of sensitive information.
2
How do I fix CVE-2024-37110?
To remediate CVE-2024-37110, upgrade WishList Member X to version 3.26.7 or higher.
3
What software is affected by CVE-2024-37110?
CVE-2024-37110 affects WishList Member X versions prior to 3.26.7.
4
Can the CVE-2024-37110 vulnerability lead to data breaches?
Yes, CVE-2024-37110 can potentially lead to unauthorized access to sensitive data.
5
Is CVE-2024-37110 specific to a particular platform?
CVE-2024-37110 affects the WishList Member X plugin used with WordPress.