IgniteUp – Coming Soon and Maintenance Mode <= 3.4.0 - Information Disclosure

2019-11-10 00:00
Jerome Bruandet

Strategic Overview

Status
Patched in 3.4.1
Affected Version<= 3.4.0
CVSS5.3Medium
CVECVE-2019-17235
View all IgniteUp – Coming Soon and Maintenance Mode vulnerabilities

Vulnerability Overview

includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure.

Technical Analysis

REMEDIATION: Update to version 3.4.1, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C