← back
CVE-2022-0594

Shareaholic < 9.7.6 - Information Disclosure

EPSS 1.5%CWE-863
The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve various information such as the list of active plugins, various version like PHP, cURL, WP etc.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →