CVE-2024-2088
22.05.2024, 07:15
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.3 via the 'nxs_getExpSettings' function. This makes it possible for authenticated attackers, with subscriber access and above, to extract sensitive data including social network API keys and secrets.Enginsight
Vendor | Product | Version |
---|---|---|
nextscripts | social_networks_auto_poster | 𝑥 < 4.4.4 |
𝑥
= Vulnerable software versions
References