CVE-2024-2107

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Mar 12, 2024
Updated: Mar 13, 2024

Summary

CVE-2024-2107 is a vulnerability affecting the Blossom Spa theme for WordPress. This issue, present in versions up to 1.3.4, allows unauthenticated attackers to extract sensitive data. The vulnerability stems from generated source code, which can be exploited to access contents of password-protected or scheduled posts. This exposure of sensitive information poses a significant security risk for WordPress sites using the Blossom Spa theme. It is recommended that users update to the latest theme version to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share