CVE-2023-4668

The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai-debug-processing-fe URL parameter. This can allow unauthenticated attackers to extract sensitive data including installed plugins (present and active), active theme, various plugin settings, WordPress version, as well as some server settings such as memory limit, installation paths.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ad_inserter_project:ad_inserter:*:*:*:*:*:wordpress:*:*

History

27 Oct 2023, 18:46

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-862
First Time Ad Inserter Project ad Inserter
Ad Inserter Project
References (MISC) https://www.wordfence.com/threat-intel/vulnerabilities/id/ce457c98-c55b-4b71-a80b-393eceb9effd?source=cve - (MISC) https://www.wordfence.com/threat-intel/vulnerabilities/id/ce457c98-c55b-4b71-a80b-393eceb9effd?source=cve - Third Party Advisory
References (MISC) https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=2969942%40ad-inserter%2Ftags%2F2.7.31&old=2922718%40ad-inserter%2Ftrunk - (MISC) https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=2969942%40ad-inserter%2Ftags%2F2.7.31&old=2922718%40ad-inserter%2Ftrunk - Patch
CPE cpe:2.3:a:ad_inserter_project:ad_inserter:*:*:*:*:*:wordpress:*:*

20 Oct 2023, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-20 08:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-4668

Mitre link : CVE-2023-4668

CVE.ORG link : CVE-2023-4668


JSON object : View

Products Affected

ad_inserter_project

  • ad_inserter
CWE
CWE-862

Missing Authorization