CVE · Medium

CVE-2024-3682 — WP Staging Pro [wp-staging-pro] < 5.5.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-3682 WP Staging Pro [wp-staging-pro] < 5.5.0 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 5.5.0 5.5.0 2024-04-25

CVE-2024-3682

WP Staging Pro versions prior to 5.5.0 contain a sensitive information exposure vulnerability in the ajaxSendReport function that allows unauthenticated attackers to access log files containing system details and license keys. The vulnerability can be exploited only if a site administrator has previously enabled the automatic log file submission feature through the Contact Us function. Affected users should update to version 5.5.0 or later to remediate this issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.