Vulnerability Description
The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve various information such as the list of active plugins, various version like PHP, cURL, WP etc.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Shareaholic | Shareaholic | < 9.7.6 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/4de9451e-2c8d-4d99-a255-b027466d29b1ExploitThird Party Advisory
- https://wpscan.com/vulnerability/4de9451e-2c8d-4d99-a255-b027466d29b1ExploitThird Party Advisory
FAQ
What is CVE-2022-0594?
CVE-2022-0594 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9....
How severe is CVE-2022-0594?
CVE-2022-0594 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-0594?
Check the references section above for vendor advisories and patch information. Affected products include: Shareaholic Shareaholic.