Vulnerabilities (CVE)

Filtered by CWE-1230
Total 24 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-10324 1 Rometheme 1 Romethemekit For Elementor 2026-06-17 N/A 4.3 MEDIUM
The RomethemeKit For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.5.2 via the register_controls function in widgets/offcanvas-rometheme.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.
CVE-2023-6962 1 Joomunited 1 Wp Meta Seo 2026-06-17 N/A 5.3 MEDIUM
The WP Meta SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.12 via the meta description. This makes it possible for unauthenticated attackers to disclose potentially sensitive information via the meta description of password-protected posts.
CVE-2023-50458 1 Dradisframework 1 Dradis 2026-06-17 N/A 3.5 LOW
In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.
CVE-2023-1974 1 Answer 1 Answer 2026-06-17 N/A 6.5 MEDIUM
Exposure of Sensitive Information Through Metadata in GitHub repository answerdev/answer prior to 1.0.8.