Skip to content
CloudflareGHSA-h2fj-7r3m-7gf2

Information disclosure of Cloudflare API for low privileged users

High8.1CVE-2024-0212 · Published Jan 29, 2024

### Impact The Cloudflare Wordpress plugin was found to be vulnerable to improper authentication. The vulnerability enables attackers with a lower privileged account to access data from the Cloudflare API. ### Patches The issue has been fixed in the latest version of the plugin https://github.com/cloudflare/Cloudflare-WordPress/releases/tag/v4.12.3

GitHub advisory

Affected versions

PackageAffectedFixed in
Cloudflare-WordPress
Product
< 4.12.34.12.3
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-284

More Cloudflare advisories

All Cloudflare
Advisory
Unlimited resource allocation by QUIC CRYPTO frames flooding
Medium5.9Mar 12, 2024
Unbounded storage of information related to connection ID retirement in quiche
Low3.7Mar 12, 2024
Kyber: timing side-channel (kyberslash2)
HighJan 8, 2024
Arbitrary remote code execution within `wrangler dev` Workers sandbox
High8.5Dec 29, 2023
Arbitrary remote file read in Wrangler dev server
Medium6.9Dec 29, 2023
Server-Side Request Forgery (SSRF) in Miniflare
High8.0Dec 29, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.