CVE-2024-2109

The Booster Extension plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.0 via the 'booster_extension_authorbox_shortcode_display' function. This makes it possible for unauthenticated attackers to extract sensitive data including user emails
Configurations

No configuration.

History

08 Apr 2026, 18:20

Type Values Removed Values Added
References
  • () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3053100%40booster-extension&new=3053100%40booster-extension&sfp_email=&sfph_mail= -
CWE CWE-862

21 Nov 2024, 09:09

Type Values Removed Values Added
References () https://plugins.trac.wordpress.org/browser/booster-extension/tags/1.2.0/inc/frontend/author-box-shortcode.php - () https://plugins.trac.wordpress.org/browser/booster-extension/tags/1.2.0/inc/frontend/author-box-shortcode.php -
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/89458095-2efe-4162-961a-7dc80852d312?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/89458095-2efe-4162-961a-7dc80852d312?source=cve -
Summary
  • (es) El complemento Booster Extension para WordPress es vulnerable a la exposición de información confidencial en todas las versiones hasta la 1.2.0 incluida a través de la función 'booster_extension_authorbox_shortcode_display'. Esto hace posible que atacantes no autenticados extraigan datos confidenciales, incluidos los correos electrónicos de los usuarios.

02 May 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-02 17:15

Updated : 2026-04-15 00:35


NVD link : CVE-2024-2109

Mitre link : CVE-2024-2109

CVE.ORG link : CVE-2024-2109


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization