Description
The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.1 via the 'get_legacy_cookies' function. This makes it possible for unauthenticated attackers to extract sensitive data including titles and permalinks of private, password-protected, pending, and draft posts.
Problem types
CWE-284 Improper Access Control
Product status
* (semver)
Timeline
| 2024-12-10: | Disclosed |
Credits
Francesco Carlucci
References
www.wordfence.com/...-6afa-4686-8e6a-01edab2dcc96?source=cve
plugins.trac.wordpress.org/...-posts/trunk/inc/namespace.php
plugins.trac.wordpress.org/changeset/3205041/