Lucene search

K
wpvulndbWpvulndbWPVDB-ID:2CF915DC-BB6B-40FB-A876-F91110C84353
HistoryMay 22, 2024 - 12:00 a.m.

NextScripts: Social Networks Auto-Poster < 4.4.4 - Subscriber+ Sensitive Information Exposure

2024-05-2200:00:00
wpscan.com
1
nextscripts
sensitive information exposure
api keys

8.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.0%

Description The plugin is vulnerable to Sensitive Information Exposure via the ‘nxs_getExpSettings’ function. This makes it possible for authenticated attackers, with subscriber access and above, to extract sensitive data including social network API keys and secrets.

CPENameOperatorVersion
eq4.4.4

8.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.0%

Related for WPVDB-ID:2CF915DC-BB6B-40FB-A876-F91110C84353