Description
The Locker Content plugin for WordPress is vulnerable to Sensitive Information Exposure in version 1.0.0 via the 'lockerco_submit_post' AJAX endpoint. This makes it possible for unauthenticated attackers to extract content from posts that has been protected by the plugin.
Problem types
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Product status
* (semver)
Timeline
| 2025-11-24: | Disclosed |
Credits
Athiwat Tiprasaharn
References
www.wordfence.com/...-2a5d-4d17-a05b-7940d7976158?source=cve
wordpress.org/plugins/locker-content/