CVE · Medium

CVE-2024-12335 — Fusion Builder [fusion-builder] < 3.11.13

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-12335 Fusion Builder [fusion-builder] < 3.11.13 Authorization Bypass Through User-Controlled Key Medium 4.3 < 3.11.13 3.11.13 2024-12-24

CVE-2024-12335

The Fusion Builder plugin for WordPress contains an information disclosure vulnerability affecting versions 3.11.12 and earlier through the handle_clone_post() function and the fusion_blog shortcode. Authenticated users with contributor privileges or higher can bypass access restrictions and retrieve sensitive content from password-protected, private, and draft posts. The vulnerability stems from inadequate validation of which posts should be accessible to each user. Versions 3.11.13 and later contain fixes for this issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.