Vulnerability CVE-2024-3678


Published: 2024-04-26

Description:
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.4.2. This makes it possible for unauthenticated attackers to view limited information from password protected posts.

 References:
https://www.wordfence.com/threat-intel/vulnerabilities/id/2dea1bcb-14c2-4ec9-8a4d-087bac2db486?source=cve
https://plugins.trac.wordpress.org/changeset/3069574/blog2social/trunk/includes/Meta.php
https://plugins.trac.wordpress.org/changeset/3074883/blog2social/trunk/includes/Meta.php

Copyright 2026, cxsecurity.com

 

Back to Top