CVE-2024-1769

The JM Twitter Cards plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 12 via the meta description data. This makes it possible for unauthenticated attackers to view password protected post content when viewing the page source.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jmlapam:jm_twitter_cards:*:*:*:*:*:wordpress:*:*

History

23 Dec 2024, 17:21

Type Values Removed Values Added
CPE cpe:2.3:a:jmlapam:jm_twitter_cards:*:*:*:*:*:wordpress:*:*
First Time Jmlapam
Jmlapam jm Twitter Cards
References () https://wordpress.org/plugins/jm-twitter-cards/ - () https://wordpress.org/plugins/jm-twitter-cards/ - Product
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/b48e5973-6923-47cc-a660-ecc989f540f8?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/b48e5973-6923-47cc-a660-ecc989f540f8?source=cve - Third Party Advisory
CWE NVD-CWE-noinfo

21 Nov 2024, 08:51

Type Values Removed Values Added
Summary
  • (es) El complemento JM Twitter Cards para WordPress es vulnerable a la exposición de la información en todas las versiones hasta 12 incluida a través de los datos de meta descripción. Esto hace posible que atacantes no autenticados vean el contenido de la publicación protegida con contraseña cuando ven la fuente de la página.
References () https://wordpress.org/plugins/jm-twitter-cards/ - () https://wordpress.org/plugins/jm-twitter-cards/ -
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/b48e5973-6923-47cc-a660-ecc989f540f8?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/b48e5973-6923-47cc-a660-ecc989f540f8?source=cve -

05 Mar 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-05 02:15

Updated : 2024-12-23 17:21


NVD link : CVE-2024-1769

Mitre link : CVE-2024-1769

CVE.ORG link : CVE-2024-1769


JSON object : View

Products Affected

jmlapam

  • jm_twitter_cards