Lucene search

K
wpvulndbKrzysztof Zając (CERT PL)WPVDB-ID:D5B59E9E-85E5-4D26-AEBE-64757C8495FA
HistoryNov 06, 2023 - 12:00 a.m.

Simple Social Buttons < 5.1.1 - Unauthenticated Password Protected Post Access

2023-11-0600:00:00
Krzysztof Zając (CERT PL)
wpscan.com
4
plugin
password-protected
content disclosure
meta tags
unauthenticated access
software

EPSS

0.001

Percentile

17.0%

Description The plugin leaks password-protected post content to unauthenticated visitors in some meta tags

PoC

As unauthenticated, view the source of any password-protected post and see that the content of the post is disclosed in the og:description and twitter:description meta tags

EPSS

0.001

Percentile

17.0%

Related for WPVDB-ID:D5B59E9E-85E5-4D26-AEBE-64757C8495FA