← back
CVE-2022-0594

Shareaholic < 9.7.6 - Information Disclosure

EPSS 1.5%CWE-863
Vexday Risk Score
18Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS EPSS 1.5%KEV nãoPoC Nuclei simMetasploit Patch
Lifecycle
25 Jul 2022Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve various information such as the list of active plugins, various version like PHP, cURL, WP etc.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →