Insertion of sensitive information into sent data vulnerability in MarketingFire Widget Options allows Retrieve Embedded Sensitive Data.
This issue affects Widget Options: from n/a through 4.0.1.
This issue affects Widget Options: from n/a through 4.0.1.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Update the WordPress Widget Options plugin to the latest available version (at least 4.0.2).
Workaround
No workaround given by the vendor.
References
History
Wed, 17 Jun 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insertion of sensitive information into sent data vulnerability in MarketingFire Widget Options allows Retrieve Embedded Sensitive Data. This issue affects Widget Options: from n/a through 4.0.1. | |
| Title | WordPress Widget Options plugin <= 4.0.1 - Subscriber+ User Meta Data Exposure Vulnerability | |
| Weaknesses | CWE-201 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-06-17T12:45:17.649Z
Reserved: 2024-05-17T10:08:56.848Z
Link: CVE-2024-35690
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses