CVE-2024-11153

Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More <= 2.5.0 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure

The Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.0 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as logged-in users.


We have discovered 45 live websites that are affected by CVE-2024-11153.

Test my site




Affected Software

Product  Content Control
Category Wordpress Plugins
Vulnerable Domains45 live websites (100.00% of Content Control install base)
Vulnerable Versions
  • from 0 through 2.5
Vulnerable Versions Count4 versions ( 100.00% of all versions)


Common Weakness Enumeration

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor



Details

  • Published - Mar 5, 2025
  • Updated - Mar 5, 2025

Credits

  • Francesco Carlucci (finder)

CVE-2024-11153 usage by Country

United States33 websites



Cyprus4 websites
Germany3 websites
GB3 websites
Australia2 websites

CVE-2024-11153 usage by TLD

.com19 websites
.org7 websites
.co.uk4 websites
.com.au2 websites
.de2 websites
.info2 websites
.it2 websites
.net2 websites
.dk1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-11153

Top websites that are affected by CVE-2024-11153. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.org United States**,***
****.org United States***,***
***.it United States***,***
****.com United States*,***,***
********.org United States*,***,***
**************.com United States**,***,***
*********.***.au Australia**,***,***
****.**.uk United States**,***,***
*************.de Germany**,***,***
********************.com United States**,***,***
See full domain list

FAQ

CVE-2024-11153 is Exposure of Sensitive Information to an Unauthorized Actor in Content Control
A total of 45 websites have been identified as vulnerable to CVE-2024-11153, discovered through global website indexing conducted by WebTechSurvey.
Content Control is susceptible to CVE-2024-11153 vulnerability.
Content Control versions before, and including, 2.5 are vulnerable to CVE-2024-11153.