CVE-2024-33538 MEDIUM

CVE-2024-33538: WordPress Assistant – Every Day Productivity Apps plugin <= 1.4.9.1 - Sensitive Data Exposure vulnerability

Vendor Fastline Media Llc
Product Assistant – Every Day Productivity Apps
Weakness CWE-200 · Info exposure
Published April 29, 2024
Last update April 28, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Fastline Media LLC Assistant – Every Day Productivity Apps.This issue affects Assistant – Every Day Productivity Apps: from n/a through 1.4.9.1.

Explanation of Vulnerability in Simple Terms

02Summary

The Assistant productivity app for mobile devices exposes sensitive information through its network communication. An attacker on the same network or intercepting traffic can read limited confidential data without authentication. The vulnerability affects versions up to 1.4.9.1. No user interaction is required for exploitation.

What an attacker can do

03Attacker Capabilities

Read sensitive information transmitted by the app over the network.

Potential impact on your site

04Site Impact

Not applicable—this is a mobile app, not a CMS plugin or core component.

Conditions required to exploit

05Prerequisites

Network access to intercept or observe the app's traffic; no authentication required.

Key dates

06Disclosure timeline

April 29, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE