Medium severity5.3NVD Advisory· Published Mar 12, 2024· Updated Apr 8, 2026
CVE-2024-0906
CVE-2024-0906
Description
The f(x) Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.1 via the API. This makes it possible for unauthenticated attackers to obtain page and post contents of a site protected with this plugin.
Affected products
1- cpe:2.3:a:shellcreeper:f\(x\)_private_site:*:*:*:*:*:wordpress:*:*Range: <=1.2.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.wordfence.com/threat-intel/vulnerabilities/id/79c3abc6-68fa-4c51-88fa-03ab7d26cc4cnvdThird Party Advisory
- wordpress.org/plugins/fx-private-site/nvdProduct
News mentions
0No linked articles in our index yet.