← back
CVE-2022-0594CWE-863

Shareaholic < 9.7.6 - Information Disclosure

18Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 2.0%
exploitation probability
2.0%top 21% of all CVEs
observed exploitation
nono source reports it
The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve various information such as the list of active plugins, various version like PHP, cURL, WP etc.