CVE-2022-0594
Shareaholic < 9.7.6 - Information Disclosure
Vexday Risk Score
18Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS —EPSS 1.5%KEV nãoPoC —Nuclei simMetasploit —Patch —
Lifecycle
25 Jul 2022Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve various information such as the list of active plugins, various version like PHP, cURL, WP etc.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →