CVE-2024-2107

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Mar 12, 2024
Updated: Mar 13, 2024

Summary

CVE-2024-2107 is a vulnerability affecting the Blossom Spa theme for WordPress. This issue, present in versions up to 1.3.4, allows unauthenticated attackers to extract sensitive data. The vulnerability stems from generated source code, which can be exploited to access contents of password-protected or scheduled posts. This exposure of sensitive information poses a significant security risk for WordPress sites using the Blossom Spa theme. It is recommended that users update to the latest theme version to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2024-2107 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions