7.5

CVE-2013-10024

Exit Strategy Plugin exitpage.php information disclosure

WordPress Exit Strategy <= 1.55 - Information Exposure

A vulnerability has been found in Exit Strategy Plugin 1.55 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality of the file exitpage.php. The manipulation leads to information disclosure. The attack can be launched remotely. Upgrading to version 1.59 is able to address this issue. The identifier of the patch is d964b8e961b2634158719f3328f16eda16ce93ac. It is recommended to upgrade the affected component. The identifier VDB-225265 was assigned to this vulnerability.
Mögliche Gegenmaßnahme
WordPress Exit Strategy: Update to version 1.59, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Exit Strategy ProjectExit Strategy Version1.55 SwPlatformwordpress
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt WordPress Exit Strategy
Version *-1.55
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.72% 0.49
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cna@vuldb.com 3.5 2.1 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
cna@vuldb.com 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://github.com/wp-plugins/exit-strategy/commit/d964b8e961b2634158719f3328f16eda16ce93ac
Patch
https://vuldb.com/?ctiid.225265
Third Party Advisory
Permissions Required
https://vuldb.com/?id.225265
Third Party Advisory
Permissions Required
https://www.wordfence.com/threat-intel/vulnerabilities/id/bc22ffe3-bd2a-4af8-84e7-5a53b68de141
Third Party Advisory