NextScripts: Social Networks Auto-Poster <= 4.4.3 - Authenticated(Subscriber+) Sensitive Information Exposure

CVE Details

Basic Information

Title NextScripts: Social Networks Auto-Poster <= 4.4.3 - Authenticated(Subscriber+) Sensitive Information Exposure
Type cve
Published 2024-05-22T06:50:34.168Z
Modified 2024-08-01T19:03:39.186Z

Product Information

Vendor nextscripts
Product NextScripts: Social Networks Auto-Poster
Version *

CVSS Information

Base Score 8.5 (HIGH)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

AI Analysis

AI Description The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to sensitive information exposure. Authenticated attackers with subscriber access or higher can extract sensitive data, including social network API keys and secrets, due to improper access controls in the ‘nxs_getExpSettings’ function.
AI Severity High
AI Vendor WordPress Community
AI Product NextScripts: Social Networks Auto-Poster
AI Version <=4.4.3

Affected Products

  • nextscripts NextScripts: Social Networks Auto-Poster *

Additional Information

Source Wordfence

Description

The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.3 via the ‘nxs_getExpSettings’ function. This makes it possible for authenticated attackers, with subscriber access and above, to extract sensitive data including social network API keys and secrets.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.