The WP STAGING and WP STAGING Pro plugins for WordPress are vulnerable to Sensitive Information Exposure in versions up to, and including, 3.4.3, and versions up to, and including, 5.4.3, respectively, via the ajaxSendReport function. This makes it possible for unauthenticated attackers to extract sensitive data from a log file, including system information and (in the Pro version) license keys. Successful exploitation requires an administrator to have used the 'Contact Us' functionality along with the "Enable this option to automatically submit the log files." option.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | WP STAGING <= 3.4.3 and WP STAGING Pro <= 5.4.3 - Sensitive Information Exposure via Log File | |
| Weaknesses | CWE-200 |
Thu, 26 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:01:25.475Z
Reserved: 2024-04-11T21:40:26.695Z
Link: CVE-2024-3682
Updated: 2024-08-01T20:20:00.842Z
Status : Awaiting Analysis
Published: 2024-04-26T10:15:11.693
Modified: 2026-04-08T18:21:31.657
Link: CVE-2024-3682
No data.
OpenCVE Enrichment
No data.