The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.5 via the 'btn_block_duplicate_post' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract potentially sensitive data from draft, scheduled (future), private, and password protected posts.
References
Configurations
History
24 Feb 2025, 16:02
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:bplugins:button_block:*:*:*:*:*:wordpress:*:* | |
CWE | NVD-CWE-noinfo | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
First Time |
Bplugins
Bplugins button Block |
|
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/ac55e988-2b41-459b-9ab1-e5f9fdca203f?source=cve - Third Party Advisory | |
References | () https://plugins.trac.wordpress.org/changeset/3208482/button-block - Patch |
19 Dec 2024, 07:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-19 07:15
Updated : 2025-02-24 16:02
NVD link : CVE-2024-12560
Mitre link : CVE-2024-12560
JSON object : View
Products Affected
bplugins
- button_block
CWE