plugin

Host Php Info Vulnerabilities

1 known security issue reported for the Host Php Info WordPress plugin. Most recent disclosed Jan 6, 2025.

1 high

Running Host Php Info on your site? Check whether your installed version is affected.

Scan your site free

Host PHP Info <= 1.0.4 - Missing Authorization to Unauthenticated Sensitive Information Disclosure

high

The Host PHP Info plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to read configuration settings and predefined variables on the sit...

CVSS:
8.6
Affected:
up to 1.0.4
Fix:
No patched version reported
Disclosed:
Jan 6, 2025

CVE-2024-12535 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database