CVE-2024-32788 MEDIUM

CVE-2024-32788: WordPress FG Joomla to Wordpress plugin <= 4.20.2 - Sensitive Data Exposure via Log File vulnerability

Vendor Frédéric Gilles
Product FG Joomla to WordPress
Weakness CWE-532 · Sensitive info in logs
Published April 24, 2024
Last update April 28, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG Joomla to WordPress.This issue affects FG Joomla to WordPress: from n/a through 4.20.2.

Explanation of Vulnerability in Simple Terms

02Summary

The FG Joomla to WordPress plugin through version 4.20.2 exposes sensitive information in logs or error messages. An attacker with network access can read this data without authentication. The plugin does not properly restrict access to or sanitize output of sensitive details during operation or debugging.

What an attacker can do

03Attacker Capabilities

Read sensitive information exposed in plugin logs or error messages without logging in.

Potential impact on your site

04Site Impact

Sensitive data (credentials, API keys, or personal information) may be visible to unauthenticated attackers.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication or user interaction required.

Key dates

06Disclosure timeline

April 24, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE