๐Ÿ” CVE Alert

CVE-2024-7648

MEDIUM 4.3

Opal Membership <= 1.2.4 - Authenticated (Subscriber+) Information Disclosure

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

The Opal Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.4 via the private notes functionality on payments which utilizes WordPress comments. This makes it possible for authenticated attackers, with subscriber-level access and above, to view private notes via recent comments that should be restricted to just administrators.

CWE CWE-862
Vendor wpopal
Product opal membership
Published Aug 10, 2024
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for wpopal opal membership

Be the first to know when new medium vulnerabilities affecting wpopal opal membership are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

wpopal / Opal Membership
0 โ‰ค 1.2.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/d3098565-d037-4a31-af3c-00e8b93b922e?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/opal-membership/trunk/inc/class-opalmembership-ajax.php#L128 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/opal-membership/trunk/inc/mixes-functions.php#L154

Credits

Karolina Jankowska