/Vulnerability Library

Simply Static - Information Disclosure

CVE-2024-32825
Verified

Description

Patrick Posner Simply Static versions up to 3.1.3 contain a vulnerability for insertion of sensitive information into log files caused by improper handling of log data, letting attackers potentially access sensitive information, exploit requires no specific privileges.

Severity

Medium

Published Date

April 23, 2026

Template Author

pussycat0x

CVE-2024-32825.yaml
5.0Severity

CVSS Metrics

References

https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simply-static/simply-static-313-unauthenticated-information-exposurehttps://www.cve.org/CVERecord?id=CVE-2024-32825https://plugins.trac.wordpress.org/changeset/3025775/simply-static

Remediation Steps

Update to the latest version of Simply Static that addresses this issue, or apply available patches.