CVE-2024-30514 MEDIUM

CVE-2024-30514: WordPress Paid Memberships Pro – Payfast Gateway Add On plugin <= 1.4.1 - Sensitive Data Exposure via Log File vulnerability

Vendor Paid Memberships Pro
Product Paid Memberships Pro – Payfast Gateway Add On
Weakness CWE-532 · Sensitive info in logs
Published March 29, 2024
Last update April 28, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Insertion of Sensitive Information into Log File vulnerability in Paid Memberships Pro Paid Memberships Pro – Payfast Gateway Add On.This issue affects Paid Memberships Pro – Payfast Gateway Add On: from n/a through 1.4.1.

Explanation of Vulnerability in Simple Terms

02Summary

The Payfast Gateway Add-On for Paid Memberships Pro exposes sensitive payment information through improper logging or storage mechanisms. An attacker on the network can read this data without authentication. The vulnerability affects versions up to 1.4.1 and may expose customer payment details or transaction records stored insecurely by the plugin.

What an attacker can do

03Attacker Capabilities

Read sensitive payment or customer data transmitted or stored by the plugin.

Potential impact on your site

04Site Impact

Customer payment information and transaction details may be exposed to unauthorized parties.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication or user interaction required.

Key dates

06Disclosure timeline

March 29, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE