CVE · Medium

CVE-2024-35691 — Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.0.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-35691 Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.0.2 Exposure of Sensitive Information to an Unauthorized Actor Medium 6.5 < 4.0.2 4.0.2 2024-06-06

CVE-2024-35691

The Widget Options plugin for WordPress up to version 4.0.1 contains a sensitive information exposure flaw that allows unauthenticated attackers to retrieve private and draft posts along with user metadata. This vulnerability affects all versions prior to 4.0.2, where the issue has been remediated. The flaw enables unauthorized access to confidential site data without requiring authentication credentials.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.