5.3
CVE-2023-6962
- EPSS 0.39%
- Veröffentlicht 02.05.2024 17:15:08
- Zuletzt bearbeitet 06.02.2025 18:39:37
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
WP Meta SEO <= 4.5.12 - Information Exposure via Meta Description
The WP Meta SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.12 via the meta description. This makes it possible for unauthenticated attackers to disclose potentially sensitive information via the meta description of password-protected posts.
Mögliche Gegenmaßnahme
WP Meta SEO: Update to version 4.5.13, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
WP Meta SEO
Version
*-4.5.12
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Joomunited ≫ Wp Meta Seo SwPlatformwordpress Version < 4.5.13
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.39% | 0.594 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-922 Insecure Storage of Sensitive Information
The product stores sensitive information without properly limiting read or write access by unauthorized actors.