CVE-2024-53804: WordPress WP Mailster plugin <= 1.8.16.0 - Sensitive Data Exposure vulnerability
Published Dec 6, 2024
·Updated
Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster wp-mailster allows Retrieve Embedded Sensitive Data.This issue affects WP Mailster: from n/a through <= 1.8.16.0.
Affected Software
3 affected components
Wpmailster Wp Mailster Wordpress<1.8.17
brandtoss WP Mailster<=1.8.16.0
WordPress WP Mailster<=1.8.16.0
Remediation
Information
Update the WordPress WP Mailster plugin to the latest available version (at least 1.8.17.0).
Event History
Dec 6, 2024
CVE Published
via MITRE·01:05 PM
Data Sourced
via MITRE·01:05 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-53804?
CVE-2024-53804 is considered a moderate severity vulnerability due to its ability to expose sensitive data.
2
How do I fix CVE-2024-53804?
To fix CVE-2024-53804, update WP Mailster to version 1.8.17 or later.
3
What kind of data is exposed in CVE-2024-53804?
CVE-2024-53804 allows the retrieval of embedded sensitive data sent through the WP Mailster plugin.
4
Which versions of WP Mailster are affected by CVE-2024-53804?
WP Mailster versions up to and including 1.8.16.0 are affected by CVE-2024-53804.
5
Who is the vendor of the product vulnerable to CVE-2024-53804?
The vendor of the vulnerable product is Brandtoss.