CVE-2014-5337
UnknownEPSS 16.99%
Last modified
CVE-2014-5337 is a vulnerability of currently unknown severity. The WordPress Mobile Pack plugin before 2.0.2 for WordPress does not properly restrict access to password protected posts, which allows remote attackers to obtain sensitive information via an exportarticles action to export/content.php.. EPSS estimates a 16.99% chance of exploitation in the next 30 days.
Description
The WordPress Mobile Pack plugin before 2.0.2 for WordPress does not properly restrict access to password protected posts, which allows remote attackers to obtain sensitive information via an exportarticles action to export/content.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wordpress Mobile Pack Project | Wordpress Mobile Pack | <= 2.0.1 |
| Wordpress Mobile Pack Project | Wordpress Mobile Pack | 1.2.0 |
| Wpmobilepack | Wordpress Mobile Pack | 1.0.8223 |
| Wpmobilepack | Wordpress Mobile Pack | 1.1.1 |
| Wpmobilepack | Wordpress Mobile Pack | 1.1.2 |
| Wpmobilepack | Wordpress Mobile Pack | 1.1.3 |
| Wpmobilepack | Wordpress Mobile Pack | 1.1.9 |
| Wpmobilepack | Wordpress Mobile Pack | 1.1.91 |
| Wpmobilepack | Wordpress Mobile Pack | 1.1.92 |
| Wpmobilepack | Wordpress Mobile Pack | 1.2.1 |
| Wpmobilepack | Wordpress Mobile Pack | 1.2.3 |
| Wpmobilepack | Wordpress Mobile Pack | 1.2.4 |
| Wpmobilepack | Wordpress Mobile Pack | 1.2.5 |
| Wpmobilepack | Wordpress Mobile Pack | 2.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-5337?
The WordPress Mobile Pack plugin before 2.0.2 for WordPress does not properly restrict access to password protected posts, which allows remote attackers to obtain sensitive information via an exportarticles action to export/content.php.
How severe is CVE-2014-5337?
Severity scoring for CVE-2014-5337 is pending analysis. The EPSS model estimates a 16.99% probability of exploitation in the next 30 days.
How do I fix CVE-2014-5337?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-5331Cross-site scripting (XSS) vulnerability in Aflax allows rem…
- CVE-2014-5332Race condition in NVMap in NVIDIA Tegra Linux Kernel 3.10 al…
- CVE-2014-5333Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.…
- CVE-2014-5334FreeNAS before 9.3-M3 has a blank admin password, which allo…
- CVE-2014-5335Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2014-5336Monkey HTTP Server before 1.5.3, when the File Descriptor Ta…
- CVE-2014-5338Multiple cross-site scripting (XSS) vulnerabilities in the m…
- CVE-2014-5339Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 allows remo…
- CVE-2014-5340The wato component in Check_MK before 1.2.4p4 and 1.2.5 befo…
- CVE-2014-5341The SFTP external storage driver (files_external) in ownClou…
- CVE-2014-5342Aruba Networks ClearPass before 6.3.5 and 6.4.x before 6.4.1…
- CVE-2014-5343Cross-site scripting (XSS) vulnerability in Feng Office allo…
Are you affected by CVE-2014-5337?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
