PatchSiren cyber security CVE debrief
CVE-2024-35690 MarketingFire CVE debrief
CVE-2024-35690 is a medium-severity vulnerability in the MarketingFire Widget Options plugin for WordPress, affecting versions from n/a to 4.0.1. The issue allows for the retrieval of embedded sensitive data due to the insertion of sensitive information into sent data. Organizations using this plugin should take immediate action to mitigate potential risks. The vulnerability has a CVSS score of 6.5 and is classified as CWE-201. Users of the affected plugin versions should update to a patched version as soon as possible.
- Vendor
- MarketingFire
- Product
- Widget Options
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-06-17
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-06-17
Who should care
Administrators and security teams of WordPress installations using the MarketingFire Widget Options plugin, especially those with subscriber or lower-privileged user accounts, should be aware of this vulnerability and take steps to protect their sites.
Technical summary
The vulnerability, CVE-2024-35690, is an Insertion of sensitive information into sent data issue in the MarketingFire Widget Options plugin. It affects versions from n/a through 4.0.1 and allows for the retrieval of embedded sensitive data. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, indicating a medium severity level with a score of 6.5. The weakness is classified as CWE-201.
Defensive priority
Medium
Recommended defensive actions
- Update the MarketingFire Widget Options plugin to a version beyond 4.0.1.
- Review and restrict access to sensitive data within the plugin's settings.
- Monitor for any suspicious activity related to the plugin.
- Implement additional security measures such as Web Application Firewalls (WAFs).
- Regularly update all plugins and themes on WordPress installations.
- Limit user privileges to the minimum required for their role.
Evidence notes
The information provided is based on data from official sources, including the CVE.org and NVD. The CVE record and NVD detail pages provide comprehensive information about the vulnerability. Additional mitigation details can be found on the Patchstack website.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-35690 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-35690
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-35690 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-35690
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.