plugin

Obfuscate Email Vulnerabilities

2 known security issues reported for the Obfuscate Email WordPress plugin. Most recent disclosed Aug 9, 2024.

1 medium

Running Obfuscate Email on your site? Check whether your installed version is affected.

Scan your site free

Obfuscate Email [obfuscate-email] <= 3.8.1 (unfixed + closed)

unknown

[en] The Obfuscate Email plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.8.1. This is due to the plugin allowing direct access to the bootstrap.php file which has display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the w...

Affected:
up to 3.8.1
Fix:
No patched version reported
Disclosed:
Aug 9, 2024

CVE-2024-7413 on NVD →

Obfuscate Email <= 3.8.1 - Unauthenticated Full Path Disclosure

medium

The Obfuscate Email plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.8.1. This is due to the plugin allowing direct access to the bootstrap.php file which has display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web ap...

CVSS:
5.3
Affected:
up to 3.8.1
Fix:
No patched version reported
Disclosed:
Aug 8, 2024

CVE-2024-7413 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database