The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.58 via the wp_ajax_nopriv_related_post_ajax_get_post_ids AJAX action. This makes it possible for unauthenticated attackers to extract sensitive data including titles of posts in draft status.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Dec 2024 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Pickplugins
Pickplugins post Grid Combo |
|
CPEs | cpe:2.3:a:pickplugins:post_grid_combo:-:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Pickplugins
Pickplugins post Grid Combo |
|
Metrics |
ssvc
|
Thu, 05 Dec 2024 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.58 via the wp_ajax_nopriv_related_post_ajax_get_post_ids AJAX action. This makes it possible for unauthenticated attackers to extract sensitive data including titles of posts in draft status. | |
Title | Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins <= 2.0.58 - Sensitive Information Exposure | |
Weaknesses | CWE-284 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-12-05T08:23:59.347Z
Updated: 2024-12-05T11:26:42.636Z
Reserved: 2024-11-06T19:03:27.237Z
Link: CVE-2024-10937
Vulnrichment
Updated: 2024-12-05T11:26:39.332Z
NVD
Status : Received
Published: 2024-12-05T09:15:04.377
Modified: 2024-12-05T09:15:04.377
Link: CVE-2024-10937
Redhat
No data.