Contact Form 7 – Dynamic Text Extension <= 4.5 - Information Disclosure via Shortcode
2024-11-05 09:02
Francesco CarlucciStrategic Overview
StatusPatched in 4.5.1
Affected PluginContact Form 7 – Dynamic Text Extension
Affected Version
<= 4.5CVSS4.3Medium
CVE
CVE-2024-10084Vulnerability Overview
The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Basic Information Disclosure in all versions up to, and including, 4.5 via the CF7_get_post_var shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract the titles and text contents of private and password-protected posts, they do not own.
Technical Analysis
REMEDIATION: Update to version 4.5.1, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C