CVE-2024-1587

The Newsmatic theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.0 via the 'newsmatic_filter_posts_load_tab_content'. This makes it possible for unauthenticated attackers to view draft posts and post content.
Configurations

Configuration 1 (hide)

cpe:2.3:a:blazethemes:newsmatic:*:*:*:*:*:wordpress:*:*

History

07 Apr 2025, 13:50

Type Values Removed Values Added
First Time Blazethemes newsmatic
Blazethemes
CPE cpe:2.3:a:blazethemes:newsmatic:*:*:*:*:*:wordpress:*:*
References () https://themes.trac.wordpress.org/browser/newsmatic/1.3.0/inc/template-functions.php#L634 - () https://themes.trac.wordpress.org/browser/newsmatic/1.3.0/inc/template-functions.php#L634 - Product
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/bd2ea430-48ce-43c3-ba3d-8ef5f91460ce?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/bd2ea430-48ce-43c3-ba3d-8ef5f91460ce?source=cve - Third Party Advisory

26 Feb 2025, 19:15

Type Values Removed Values Added
CWE CWE-862

Information

Published : 2024-04-09 19:15

Updated : 2025-04-07 13:50


NVD link : CVE-2024-1587

Mitre link : CVE-2024-1587

CVE.ORG link : CVE-2024-1587


JSON object : View

Products Affected

blazethemes

  • newsmatic
CWE
CWE-862

Missing Authorization