Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47017 | The Hide My Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 due to the plugin not restricting access to the REST API when password protection is enabled. This makes it possible for unauthenticated attackers to gain unauthorized access to the site. |
Wed, 21 Aug 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 21 Aug 2024 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Hide My Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 due to the plugin not restricting access to the REST API when password protection is enabled. This makes it possible for unauthenticated attackers to gain unauthorized access to the site. | |
| Title | Hide My Site <= 2.2 - Unauthenticated Information Exposure | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:45:11.748Z
Reserved: 2024-06-11T16:58:01.888Z
Link: CVE-2024-5880
Updated: 2024-08-21T20:37:42.783Z
Status : Deferred
Published: 2024-08-21T06:15:07.633
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-5880
No data.
OpenCVE Enrichment
No data.
EUVD