← Back to CVE List

CVE-2024-11154

Published: 2024-11-20T14:15Z
Last Modified: 2024-11-21T13:57Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.15 via the 'actAjaxRevisionDiffs' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive data including revisions of posts and pages. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt