Lucene search

K
wpexploitKrzysztof Zając (CERT PL)WPEX-ID:D5B59E9E-85E5-4D26-AEBE-64757C8495FA
HistoryNov 06, 2023 - 12:00 a.m.

Simple Social Buttons < 5.1.1 - Unauthenticated Password Protected Post Access

2023-11-0600:00:00
Krzysztof Zając (CERT PL)
57
social buttons
unauthenticated
password protected
post access
exploit

EPSS

0.001

Percentile

17.0%

Description The plugin leaks password-protected post content to unauthenticated visitors in some meta tags

As unauthenticated, view the source of any password-protected post and see that the content of the post is disclosed in the og:description and twitter:description meta tags

EPSS

0.001

Percentile

17.0%

Related for WPEX-ID:D5B59E9E-85E5-4D26-AEBE-64757C8495FA