VulnerabilityModified
CVE-2014-5337
The WordPress Mobile Pack plugin before 2.0.2 for WordPress does not properly restrict access to password protected posts, which allows remote attackers to obtain sensitive information via an exportarticles action to export/content.php.
MEDIUM 5.0EPSS 17.0%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 17.0%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
The WordPress Mobile Pack plugin before 2.0.2 for WordPress does not properly restrict access to password protected posts, which allows remote attackers to obtain sensitive information via an exportarticles action to export/content.php.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 16.99% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- wordpress mobile pack project/wordpress mobile pack · wpmobilepack/wordpress mobile pack
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/60584
- http://wordpress.org/plugins/wordpress-mobile-pack/changelog/Patch
- http://www.securityfocus.com/bid/69292
- https://security.dxw.com/advisories/information-disclosure-vulnerability-in-wordpress-mobile-pack-allows-anybody-to-read-password-protected-posts/Exploit
- http://secunia.com/advisories/60584
- http://wordpress.org/plugins/wordpress-mobile-pack/changelog/Patch
- http://www.securityfocus.com/bid/69292
- https://security.dxw.com/advisories/information-disclosure-vulnerability-in-wordpress-mobile-pack-allows-anybody-to-read-password-protected-posts/Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.