CVE-2024-11089

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows unauthenticated attackers to access sensitive information from posts that should only be visible to logged-in users. It occurs because the WordPress search feature can expose this restricted content, affecting all versions of the Anonymous Restricted Content plugin up to 1.6.5.

Technical Description

The Anonymous Restricted Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.5 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to logged-in users.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
Confidentiality ImpactLow
Integrity ImpactNone
Availability ImpactNone
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$724($500-$1K)
Vendor Response
Grade FPatched in 476 days

Quick Information

Published

Nov 21, 2024

over 1 year ago

Last Modified

Mar 12, 2026

26 days ago

Vendor

cayenne

Product

anonymous restricted content