CVE-2013-10024 LOW

CVE-2013-10024: Exit Strategy Plugin exitpage.php information disclosure

Vendor N/A
Product Exit Strategy Plugin
Weakness CWE-200 · Info exposure
Published April 8, 2023
Last update February 7, 2025

CVSS base score

3.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

A vulnerability has been found in Exit Strategy Plugin 1.55 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality of the file exitpage.php. The manipulation leads to information disclosure. The attack can be launched remotely. Upgrading to version 1.59 is able to address this issue. The identifier of the patch is d964b8e961b2634158719f3328f16eda16ce93ac. It is recommended to upgrade the affected component. The identifier VDB-225265 was assigned to this vulnerability.

Explanation of Vulnerability in Simple Terms

02Summary

The Exit Strategy Plugin contains an information exposure vulnerability that allows authenticated users with low privileges to view sensitive data through the plugin's interface. The vulnerability requires user interaction and affects only the confidentiality of information, not integrity or availability. A patch version is not currently available.

What an attacker can do

03Attacker Capabilities

View sensitive information the attacker should not have access to.

Potential impact on your site

04Site Impact

Authenticated users can access private data through the plugin; patch status unknown.

Conditions required to exploit

05Prerequisites

Attacker must be logged in with low-level user privileges and trick a user into clicking a malicious link.

Key dates

06Disclosure timeline

April 8, 2023 CVE published
February 7, 2025 Record updated

Related vulnerabilities

08Related CVE