What the vulnerability does
01Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StellarWP Membership Plugin – Restrict Content plugin <= 3.2.7 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StellarWP Membership Plugin – Restrict Content plugin <= 3.2.7 versions.
Explanation of Vulnerability in Simple Terms
The Membership Plugin – Restrict Content for WordPress contains an information exposure vulnerability in versions up to 3.2.7. The plugin fails to properly restrict access to sensitive data, allowing unauthenticated attackers to read information that should be protected. This affects sites using the plugin without additional access controls. Update to a version newer than 3.2.7 to resolve the issue.
What an attacker can do
Read sensitive information that should be restricted to authorized users.
Potential impact on your site
Unauthorized visitors can access protected content or data meant only for members.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities