The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve various information such as the list of active plugins, various version like PHP, cURL, WP etc.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-02T23:32:46.451Z
Reserved: 2022-02-14T00:00:00
Link: CVE-2022-0594
No data.
Status : Modified
Published: 2022-07-25T13:15:08.030
Modified: 2024-11-21T06:38:59.233
Link: CVE-2022-0594
No data.
OpenCVE Enrichment
No data.
Weaknesses