The Graphene theme for WordPress is vulnerable to unauthorized access of data via meta tag in all versions up to, and including, 2.9.2. This makes it possible for unauthenticated individuals to obtain post contents of password protected posts via the generated source.
History

Wed, 08 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Title Graphene <= 2.9.2 - Missing Authorization
Weaknesses CWE-862

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-04-09T18:59:29.548Z

Updated: 2026-04-08T17:29:19.413Z

Reserved: 2024-02-28T18:51:40.153Z

Link: CVE-2024-1984

cve-icon Vulnrichment

Updated: 2024-08-01T18:56:22.550Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-09T19:15:21.513

Modified: 2026-04-08T19:20:56.040

Link: CVE-2024-1984

cve-icon Redhat

No data.