CVE-2024-31249 MEDIUM

CVE-2024-31249: WordPress Subscribe To Comments Reloaded plugin <= 220725 - Sensitive Data Exposure vulnerability

Vendor Wpkube
Product Subscribe To Comments Reloaded
Weakness CWE-532 · Sensitive info in logs
Published April 10, 2024
Last update April 28, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Insertion of Sensitive Information into Log File vulnerability in WPKube Subscribe To Comments Reloaded.This issue affects Subscribe To Comments Reloaded: from n/a through 220725.

Explanation of Vulnerability in Simple Terms

02Summary

Subscribe To Comments Reloaded contains an insertion of sensitive information into log files. An unauthenticated attacker on the network can read log entries containing user data without special privileges or user interaction. The vulnerability affects versions up to 220725. Update to a version newer than the affected range.

What an attacker can do

03Attacker Capabilities

Read sensitive user information written to log files accessible over the network.

Potential impact on your site

04Site Impact

User data may be exposed in log files readable by attackers without site access.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication or user interaction required.

Key dates

06Disclosure timeline

April 10, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE