CVE-2024-32825: high-severity vulnerability in Simply Static
WordPress Simply Static plugin <= 3.1.3 - Sensitive Data Exposure via Log File vulnerability
Published · Updated
Patch soon. It has a working public exploit.
The Simply Static WordPress plugin up to version 3.1.3 accidentally exposes sensitive information in log files that can be accessed by unauthorized users. This could reveal private data like credentials or configuration details.
CWE-201 vulnerability in Simply Static <= 3.1.3 allows unauthenticated or low-privileged attackers to access sensitive data (credentials, API keys, configuration parameters) through publicly or insufficiently protected log files. The plugin fails to sanitize or restrict access to logs containing sensitive information, enabling information disclosure without requiring code execution or complex exploitation.
In the same product, most dangerous first.