Cyber Posture

CVE-2024-56300

High

Published: 07 January 2025

Published
07 January 2025
Modified
23 April 2026
KEV Added
Patch
CVSS Score 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.0054 67.5th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Description

Insertion of Sensitive Information Into Sent Data vulnerability in wpspin Post/Page Copying Tool postpage-import-export-with-custom-fields-taxonomies allows Retrieve Embedded Sensitive Data.This issue affects Post/Page Copying Tool: from n/a through <= 2.0.0.

Security Summary

CVE-2024-56300 is an Insertion of Sensitive Information Into Sent Data vulnerability (CWE-201) in the WordPress plugin Post/Page Copying Tool, also known as postpage-import-export-with-custom-fields-taxonomies. This issue affects all versions of the plugin from n/a through 2.0.0. The vulnerability enables the retrieval of embedded sensitive data and carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), indicating high severity due to the potential for significant confidentiality impact.

An unauthenticated attacker with network access can exploit this vulnerability with low attack complexity and without requiring user interaction. Exploitation allows the attacker to retrieve sensitive information embedded in data sent by the plugin, potentially exposing confidential details from WordPress sites running the affected plugin.

The Patchstack advisory provides further details on this vulnerability, including vulnerability-specific information for the Post/Page Copying Tool plugin version 2.0.0: https://patchstack.com/database/Wordpress/Plugin/postpage-import-export-with-custom-fields-taxonomies/vulnerability/wordpress-post-page-copying-tool-plugin-2-0-0-sensitive-data-exposure-vulnerability?_s_id=cve.

Details

CWE(s)
CWE-201

References