CloudflareGHSA-h2fj-7r3m-7gf2
Information disclosure of Cloudflare API for low privileged users
High8.1CVE-2024-0212 · Published Jan 29, 2024
### Impact The Cloudflare Wordpress plugin was found to be vulnerable to improper authentication. The vulnerability enables attackers with a lower privileged account to access data from the Cloudflare API. ### Patches The issue has been fixed in the latest version of the plugin https://github.com/cloudflare/Cloudflare-WordPress/releases/tag/v4.12.3
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Cloudflare-WordPress Product | < 4.12.3 | 4.12.3 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-284
More Cloudflare advisories
All Cloudflare| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 122024 | Unlimited resource allocation by QUIC CRYPTO frames flooding | Medium5.9 | 0.19.2+1 more |
| Mar 122024 | Unbounded storage of information related to connection ID retirement in quiche | Low3.7 | 0.19.2+1 more |
| Jan 82024 | Kyber: timing side-channel (kyberslash2) | High | 1.3.7 |
| Dec 292023 | Arbitrary remote code execution within `wrangler dev` Workers sandbox | High8.5 | 3.19.0+1 more |
| Dec 292023 | Arbitrary remote file read in Wrangler dev server | Medium6.9 | 3.19.0 |
| Dec 292023 | Server-Side Request Forgery (SSRF) in Miniflare | High8.0 | 3.20231030.2 |