CVE-2024-2920

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.4.9.3 due to the plugin uploading user supplied files to a publicly accessible directory in wp-content without any restrictions. This makes it possible for unauthenticated attackers to view files uploaded by other users which may contain sensitive information.
Configurations

No configuration.

History

08 Apr 2026, 18:21

Type Values Removed Values Added
CWE CWE-200

21 Nov 2024, 09:10

Type Values Removed Values Added
Summary
  • (es) El complemento WP-Members Membership Plugin para WordPress es vulnerable a la exposición de la información en todas las versiones hasta la 3.4.9.3 incluida debido a que el complemento carga archivos proporcionados por el usuario en un directorio de acceso público en wp-content sin ninguna restricción. Esto hace posible que atacantes no autenticados vean archivos cargados por otros usuarios que pueden contener información confidencial.
References () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3074215%40wp-members&new=3074215%40wp-members&sfp_email=&sfph_mail= - () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3074215%40wp-members&new=3074215%40wp-members&sfp_email=&sfph_mail= -
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/4319fa2e-8826-4100-9156-cbe80582367e?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/4319fa2e-8826-4100-9156-cbe80582367e?source=cve -

26 Apr 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-26 08:15

Updated : 2026-04-15 00:35


NVD link : CVE-2024-2920

Mitre link : CVE-2024-2920

CVE.ORG link : CVE-2024-2920


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor