CVE-2024-31298 MEDIUM

CVE-2024-31298: WordPress User Spam Remover plugin <= 1.0 - Sensitive Data Exposure via Log File vulnerability

Vendor Joel Hardi
Product User Spam Remover
Weakness CWE-532 · Sensitive info in logs
Published April 10, 2024
Last update April 28, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Insertion of Sensitive Information into Log File vulnerability in Joel Hardi User Spam Remover.This issue affects User Spam Remover: from n/a through 1.0.

Explanation of Vulnerability in Simple Terms

02Summary

User Spam Remover version 1.0 and earlier logs sensitive information in a way that can be accessed without authentication. An attacker on the network can read this logged data, potentially exposing user details or system information. Update to a version newer than 1.0 if available from the vendor.

What an attacker can do

03Attacker Capabilities

Read sensitive logged information without needing to log in to the site.

Potential impact on your site

04Site Impact

User data or system details logged by the plugin may be exposed to unauthenticated attackers.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication or user interaction required.

Key dates

06Disclosure timeline

April 10, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE