CVE-2024-11154

Source
https://cve.org/CVERecord?id=CVE-2024-11154
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-11154.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-11154
Published
2024-11-20T13:55:13Z
Modified
2026-08-12T03:51:23Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes <= 3.5.15 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure
Details

The PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.15 via the 'actAjaxRevisionDiffs' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive data including revisions of posts and pages.

Database specific
{
    "cna_assigner": "Wordfence",
    "cwe_ids": [
        "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/11xxx/CVE-2024-11154.json"
}
References

Affected packages

Git / github.com/publishpress/publishpress-revisions

Affected ranges

Type
GIT
Repo
https://github.com/publishpress/publishpress-revisions
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.5.15"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v1.*
v1.3.8
v2.*
v2.0.10
v2.0.12
v2.0.4
v2.0.5
v2.0.5-dev
v2.0.5-release
v2.0.9
v2.3
v2.3.10
v2.3.11
v2.3.12
v2.3.8
v2.3.9
v2.4
v2.4.1
v2.4.1-beta2
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.5
v2.5.1
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.5-beta
v2.6
v2.6.1
v2.6.2
v3.*
v3.0
v3.0.1
v3.0.10
v3.0.12
v3.0.13
v3.0.14
v3.0.15
v3.0.16
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.8
v3.0.9
v3.1
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.3
v3.4
v3.4.1
v3.5
v3.5.1
v3.5.11
v3.5.13
v3.5.14
v3.5.15
v3.5.2
v3.5.3
v3.5.3-rc2
v3.5.4
v3.5.5
v3.5.6
v3.5.7
v3.5.8
v3.5.8.1
v3.5.8.2
v3.5.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-11154.json"