Vulnerabilities > CVE-2024-1587 - Unspecified vulnerability in Blazethemes Newsmatic
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The Newsmatic theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.0 via the 'newsmatic_filter_posts_load_tab_content'. This makes it possible for unauthenticated attackers to view draft posts and post content.
Vulnerable Configurations
References
- https://themes.trac.wordpress.org/browser/newsmatic/1.3.0/inc/template-functions.php#L634
- https://themes.trac.wordpress.org/browser/newsmatic/1.3.0/inc/template-functions.php#L634
- https://www.wordfence.com/threat-intel/vulnerabilities/id/bd2ea430-48ce-43c3-ba3d-8ef5f91460ce?source=cve
- https://www.wordfence.com/threat-intel/vulnerabilities/id/bd2ea430-48ce-43c3-ba3d-8ef5f91460ce?source=cve