You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Information disclosure of Cloudflare API for low privileged users
High
ncabetecf
published
GHSA-h2fj-7r3m-7gf2Jan 29, 2024
Package
Cloudflare-WordPress
(Wordpress)
Affected versions
< 4.12.2
Patched versions
4.12.3
Description
Impact
The Cloudflare Wordpress plugin was found to be vulnerable to improper authentication. The vulnerability enables attackers with a lower privileged account to access data from the Cloudflare API.
Impact
The Cloudflare Wordpress plugin was found to be vulnerable to improper authentication. The vulnerability enables attackers with a lower privileged account to access data from the Cloudflare API.
Patches
The issue has been fixed in the latest version of the plugin https://github.com/cloudflare/Cloudflare-WordPress/releases/tag/v4.12.3