Medium severity5.3NVD Advisory· Published Mar 13, 2024· Updated Apr 8, 2026
CVE-2024-1479
CVE-2024-1479
Description
The WP Show Posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 via the wpsp_display function. This makes it possible for authenticated attackers with contributor access and above to view the contents of draft, trash, future, private and pending posts and pages.
Affected products
1- cpe:2.3:a:generatepress:wp_show_posts:*:*:*:*:*:wordpress:*:*Range: <1.1.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- plugins.trac.wordpress.org/changesetnvdPatch
- www.wordfence.com/threat-intel/vulnerabilities/id/6788e2ee-ce61-494b-8d7f-6d1144466e58nvdThird Party Advisory
- plugins.trac.wordpress.org/browser/wp-show-posts/trunk/wp-show-posts.phpnvdProduct
- plugins.trac.wordpress.org/browser/wp-show-posts/trunk/wp-show-posts.phpnvdProduct
News mentions
0No linked articles in our index yet.