CVE-2024-0978
CVE-2024-0978 is a sensitive information exposure vulnerability in the My Private Site WordPress plugin. This flaw allows unauthenticated attackers to bypass the plugin's privacy settings and access restricted content such as pages and posts. The vulnerability affects all versions of the plugin up to and including 3.0.14, posing a risk to websites relying on this plugin for content protection.
Although the CVSS score is 0, indicating minimal direct impact, the SOCRadar Vulnerability Risk Score (SVRS) of 30 suggests there is still a potential risk, particularly given the "In The Wild" tag. The SVRS considers factors beyond direct exploitability, such as observed exploitation attempts. Successful exploitation grants unauthorized access to private content, potentially leading to data breaches and compromise of sensitive information. Website administrators using the My Private Site plugin should immediately update to a patched version to mitigate this risk. The ability to view restricted data without authentication makes this a significant concern for sites prioritizing privacy.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.