boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2024-31249HIGH
WPKube Subscribe To Comments Reloaded — WordPress Subscribe To Comments Reloaded plugin <= 220725 - Sensitive Data Exposure vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0051   41.3     —
AFFECTED
  Product                         Versions  Fixed
  Subscribe To Comments Reloaded  n/a –     240119
TIMELINE
  Mar 29  Reserved by Patchstack
  Apr 10  Published (CNA: Patchstack)
  Aug 12  RESCORED — CVE-2024-31249 (WPKube Subscribe To Comments Reloaded). CVSS 5.3 → 7.5 (NVD).
CWE-532 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Modified

Description

Insertion of Sensitive Information into Log File vulnerability in WPKube Subscribe To Comments Reloaded.This issue affects Subscribe To Comments Reloaded: from n/a through 220725.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
March 29, 2024ReservedReserved by Patchstack
April 10, 2024PublishedPublished (CNA: Patchstack)
August 12, 2026RESCOREDRESCORED — CVE-2024-31249 (WPKube Subscribe To Comments Reloaded). CVSS 5.3 → 7.5 (NVD).

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
WPKubeSubscribe To Comments Reloadedn/a240119

Weaknesses

CWE-532

References (1)

Related

Authoritative record: CVE-2024-31249 at cve.org

Vendors: wpkube

Weaknesses: CWE-532

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2024-31249 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.