CVE Database /
CVE-2024-35691
CVE · Medium
CVE-2024-35691 — Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.0.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-35691
|
Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.0.2 |
Exposure of Sensitive Information to an Unauthorized Actor |
Medium
6.5
|
< 4.0.2
|
4.0.2 |
2024-06-06 |
—
|
CVE-2024-35691
The Widget Options plugin for WordPress up to version 4.0.1 contains a sensitive information exposure flaw that allows unauthenticated attackers to retrieve private and draft posts along with user metadata. This vulnerability affects all versions prior to 4.0.2, where the issue has been remediated. The flaw enables unauthorized access to confidential site data without requiring authentication credentials.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings