← back
CVE-2024-0212highCWE-284

Cloudflare WordPress plugin enables information disclosure of Cloudflare API (for low privileged users)

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.1epss 0.8%
exploitation probability
0.8%top 45% of all CVEs
observed exploitation
nono source reports it
The Cloudflare Wordpress plugin was found to be vulnerable to improper authentication. The vulnerability enables attackers with a lower privileged account to access data from the Cloudflare API.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N