CVE-2023-6289
Swift Performance Lite <= 2.3.6.14 - Unauthenticated Configuration Export
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.3EPSS 0.9%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
18 Dec 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Swift Performance Lite WordPress plugin before 2.3.6.15 does not prevent users from exporting the plugin's settings, which may include sensitive information such as Cloudflare API tokens.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products
Unknown · Swift Performance LiteWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →