CVE-2024-2920

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.4.9.3 due to the plugin uploading user supplied files to a publicly accessible directory in wp-content without any restrictions. This makes it possible for unauthenticated attackers to view files uploaded by other users which may contain sensitive information.
Configurations

No configuration.

History

No history.

Information

Published : 2024-04-26 08:15

Updated : 2026-06-17 07:25


NVD link : CVE-2024-2920

Mitre link : CVE-2024-2920

CVE.ORG link : CVE-2024-2920


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor