The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.58 via the wp_ajax_nopriv_related_post_ajax_get_post_ids AJAX action. This makes it possible for unauthenticated attackers to extract sensitive data including titles of posts in draft status.
History

Thu, 05 Dec 2024 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Pickplugins
Pickplugins post Grid Combo
CPEs cpe:2.3:a:pickplugins:post_grid_combo:-:*:*:*:*:wordpress:*:*
Vendors & Products Pickplugins
Pickplugins post Grid Combo
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 05 Dec 2024 08:45:00 +0000

Type Values Removed Values Added
Description The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.58 via the wp_ajax_nopriv_related_post_ajax_get_post_ids AJAX action. This makes it possible for unauthenticated attackers to extract sensitive data including titles of posts in draft status.
Title Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins <= 2.0.58 - Sensitive Information Exposure
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-12-05T08:23:59.347Z

Updated: 2024-12-05T11:26:42.636Z

Reserved: 2024-11-06T19:03:27.237Z

Link: CVE-2024-10937

cve-icon Vulnrichment

Updated: 2024-12-05T11:26:39.332Z

cve-icon NVD

Status : Received

Published: 2024-12-05T09:15:04.377

Modified: 2024-12-05T09:15:04.377

Link: CVE-2024-10937

cve-icon Redhat

No data.