CVE-2014-5337 describes an information disclosure vulnerability in the WordPress Mobile Pack plugin prior to version 2.0.2, affecting WordPress installations using this plugin. This flaw allows unauthenticated remote attackers to access sensitive information from password-protected posts by exploiting an improper access restriction via the exportarticles action in export/content.php. With a CVSS score of 5.0, it is a medium-severity vulnerability, easily exploitable over the network with low complexity, leading to a compromise of confidentiality. While not listed in CISA's KEV catalog, a Metasploit module exists for exploitation, and it has garnered some community discussion and media coverage, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.1CPE matchmatch criteria | cpe:2.3:a:wordpress_mobile_pack_project:wordpress_mobile_pack:*:*:*:*:*:wordpress:*:* | ||
1.2.0CPE matchmatch criteria | cpe:2.3:a:wordpress_mobile_pack_project:wordpress_mobile_pack:1.2.0:*:*:*:*:wordpress:*:* | ||
1.2.0CPE matchmatch criteria | cpe:2.3:a:wordpress_mobile_pack_project:wordpress_mobile_pack:1.2.0:b:*:*:*:wordpress:*:* | ||
1.2.0CPE matchmatch criteria | cpe:2.3:a:wordpress_mobile_pack_project:wordpress_mobile_pack:1.2.0:b2:*:*:*:wordpress:*:* | ||
1.0.8223CPE matchmatch criteria | cpe:2.3:a:wpmobilepack:wordpress_mobile_pack:1.0.8223:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.