CVE-2024-2950

BoldGrid Easy SEO – Simple and Effective SEO <= 1.6.14 - Information Exposure

mediumExposure of Sensitive Information to an Unauthorized Actor
5.3
CVSS Score
5.3
CVSS Score
medium
Severity
1.6.15
Patched in
1d
Time to patch

Description

The BoldGrid Easy SEO – Simple and Effective SEO plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.6.14 via meta information (og:description) This makes it possible for unauthenticated attackers to view the first 130 characters of a password protected post which can contain sensitive information.

CVSS Vector Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Low
Confidentiality
None
Integrity
None
Availability

Technical Details

Affected versions<=1.6.14
PublishedApril 5, 2024
Last updatedApril 6, 2024
Affected pluginboldgrid-easy-seo

Check if your site is affected.

Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.