CVE-2015-0902

The Semper Fi All in One SEO Pack plugin before 2.2.6 for WordPress does not consider the presence of password protection during generation of the Meta Description field, which allows remote attackers to obtain sensitive information by reading HTML source code.
Configurations

Configuration 1 (hide)

cpe:2.3:a:semperfiwebdesign:all_in_one_seo_pack:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 02:23

Type Values Removed Values Added
References () http://jvn.jp/en/jp/JVN75615300/index.html - Vendor Advisory () http://jvn.jp/en/jp/JVN75615300/index.html - Vendor Advisory
References () http://jvndb.jvn.jp/jvndb/JVNDB-2015-000046 - Vendor Advisory () http://jvndb.jvn.jp/jvndb/JVNDB-2015-000046 - Vendor Advisory
References () http://semperfiwebdesign.com/blog/all-in-one-seo-pack/all-in-one-seo-pack-release-history/ - Patch, Vendor Advisory () http://semperfiwebdesign.com/blog/all-in-one-seo-pack/all-in-one-seo-pack-release-history/ - Patch, Vendor Advisory

Information

Published : 2015-04-03 10:59

Updated : 2024-11-21 02:23


NVD link : CVE-2015-0902

Mitre link : CVE-2015-0902

CVE.ORG link : CVE-2015-0902


JSON object : View

Products Affected

semperfiwebdesign

  • all_in_one_seo_pack
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor