7.5

CVE-2024-7870

PixelYourSite – Your smart PIXEL (TAG) & API Manager <= 9.7.1 and PixelYourSite PRO <= 10.4.2 - Unauthenticated Information Exposure and Log Deletion

PixelYourSite – Your smart PIXEL (TAG) & API Manager <= 9.7.1 and PixelYourSite PRO <= 10.4.2 - Unauthenticated Information Exposure and Log Deletion

The PixelYourSite – Your smart PIXEL (TAG) & API Manager and the PixelYourSite PRO plugins for WordPress are vulnerable to Sensitive Information Exposure in all versions up to, and including, 9.7.1 and 10.4.2, respectively, through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files, and to delete log files.
Mögliche Gegenmaßnahme
PixelYourSite – Your smart PIXEL (TAG) & API Manager: Update to version 9.7.2, or a newer patched version
PixelYourSite Pro – Your smart PIXEL (TAG) Manager: Update to version 10.4.3, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PixelyoursitePixelyoursite SwEdition- SwPlatformwordpress Version < 9.7.2
PixelyoursitePixelyoursite SwEditionpro SwPlatformwordpress Version < 10.4.3
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt PixelYourSite – Your smart PIXEL (TAG) & API Manager
Version *-9.7.1
SystemWordPress Plugin
Produkt PixelYourSite Pro – Your smart PIXEL (TAG) Manager
Version *-10.4.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.45% 0.357
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
security@wordfence.com 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

https://github.com/WordpressPluginDirectory/pixelyoursite/blob/main/pixelyoursite/includes/logger/class-pys-logger.php#L126
Product
https://plugins.trac.wordpress.org/browser/pixelyoursite/trunk/includes/class-pys.php#L114
Product
https://plugins.trac.wordpress.org/changeset/3143047/
Patch
https://www.wordfence.com/threat-intel/vulnerabilities/id/7fd7a515-6389-4152-8dac-d5497dd94f6d?source=cve
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/7fd7a515-6389-4152-8dac-d5497dd94f6d
Third Party Advisory