vulnerability

WordPress Plugin: patreon-connect: CVE-2021-24227: Exposure of Sensitive Information to an Unauthorized Actor

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
Mar 26, 2021
Added
May 15, 2025
Modified
May 15, 2025

Description

The Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon WordPress plugin before 1.7.0 that could be abused by anyone visiting the site. Using this attack vector, an attacker could leak important internal files like wp-config.php, which contains database credentials and cryptographic keys used in the generation of nonces and cookies.

Solution

patreon-connect-plugin-cve-2021-24227
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.