CVE-2024-3679

The Premium SEO Pack – WP SEO Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.001. This makes it possible for unauthenticated attackers to view limited information from password protected posts through the social meta data.
Configurations

Configuration 1 (hide)

cpe:2.3:a:squirrly:wp_seo_plugin:*:*:*:*:*:wordpress:*:*

History

19 Sep 2024, 22:10

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 7.5
References () https://wordpress.org/plugins/premium-seo-pack/ - () https://wordpress.org/plugins/premium-seo-pack/ - Product
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/ccb65de5-bfb5-47db-87c9-ad46e65924b8?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/ccb65de5-bfb5-47db-87c9-ad46e65924b8?source=cve - Third Party Advisory
Summary
  • (es) El complemento Premium SEO Pack – WP SEO Plugin para WordPress es vulnerable a la exposición de información confidencial en todas las versiones hasta la 1.6.001 incluida. Esto permite que atacantes no autenticados vean información limitada de publicaciones protegidas con contraseña a través de los metadatos sociales.
CPE cpe:2.3:a:squirrly:wp_seo_plugin:*:*:*:*:*:wordpress:*:*
CWE NVD-CWE-noinfo
First Time Squirrly
Squirrly wp Seo Plugin

29 Aug 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-29 13:15

Updated : 2024-09-19 22:10


NVD link : CVE-2024-3679

Mitre link : CVE-2024-3679

CVE.ORG link : CVE-2024-3679


JSON object : View

Products Affected

squirrly

  • wp_seo_plugin
CWE
NVD-CWE-noinfo CWE-200

Exposure of Sensitive Information to an Unauthorized Actor