CVE-2024-1526
Hubbub Lite < 1.33.1 - Unauthenticated Password Protected Posts Access
Severity Score
5.3
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track
*SSVC
Descriptions
The Hubbub Lite WordPress plugin before 1.33.1 does not ensure that user have access to password protected post before displaying its content in a meta tag.
El complemento Hubbub Lite de WordPress anterior a 1.33.1 no garantiza que el usuario tenga acceso a una publicación protegida con contraseña antes de mostrar su contenido en una metaetiqueta.
The Hubbub Lite – Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.33.0 via opengraph tags. This makes it possible for unauthenticated attackers to view short excerpts of password protected posts.
*Credits:
Krzysztof Zając (CERT PL), WPScan
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-02-15 CVE Reserved
- 2024-03-11 CVE Published
- 2024-04-01 EPSS Updated
- 2024-08-01 CVE Updated
- 2024-08-01 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/1664697e-0ea3-4d09-b2fd-153a104ec255 | 2024-08-01 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Unknown Search vendor "Unknown" | Hubbub Lite Search vendor "Unknown" for product "Hubbub Lite" | < 1.33.1 Search vendor "Unknown" for product "Hubbub Lite" and version " < 1.33.1" | en |
Affected
|