5.3

CVE-2024-3228

Social Sharing Plugin – Kiwi <= 2.1.7 - Information Disclosure

The Social Sharing Plugin – Kiwi plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.1.7 via the 'kiwi-nw-pinterest' class. This makes it possible for unauthenticated attackers to view limited content from password protected posts.
Mögliche Gegenmaßnahme
Social Sharing Plugin – Kiwi: Update to version 2.1.8, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Social Sharing Plugin – Kiwi
Version * - 2.1.7
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WpkubeKiwi Social Share SwEditionwordpress Version < 2.1.8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.61% 0.689
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@wordfence.com 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N