CVE-2024-56300
Published: 07 January 2025
Description
Insertion of Sensitive Information Into Sent Data vulnerability in wpspin Post/Page Copying Tool postpage-import-export-with-custom-fields-taxonomies allows Retrieve Embedded Sensitive Data.This issue affects Post/Page Copying Tool: from n/a through <= 2.0.0.
Security Summary
CVE-2024-56300 is an Insertion of Sensitive Information Into Sent Data vulnerability (CWE-201) in the WordPress plugin Post/Page Copying Tool, also known as postpage-import-export-with-custom-fields-taxonomies. This issue affects all versions of the plugin from n/a through 2.0.0. The vulnerability enables the retrieval of embedded sensitive data and carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), indicating high severity due to the potential for significant confidentiality impact.
An unauthenticated attacker with network access can exploit this vulnerability with low attack complexity and without requiring user interaction. Exploitation allows the attacker to retrieve sensitive information embedded in data sent by the plugin, potentially exposing confidential details from WordPress sites running the affected plugin.
The Patchstack advisory provides further details on this vulnerability, including vulnerability-specific information for the Post/Page Copying Tool plugin version 2.0.0: https://patchstack.com/database/Wordpress/Plugin/postpage-import-export-with-custom-fields-taxonomies/vulnerability/wordpress-post-page-copying-tool-plugin-2-0-0-sensitive-data-exposure-vulnerability?_s_id=cve.
Details
- CWE(s)