WordPress Simple History Plugin RSS Feed Information Disclosure Vulnerability
BID:57628
Info
WordPress Simple History Plugin RSS Feed Information Disclosure Vulnerability
| Bugtraq ID: | 57628 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 30 2013 12:00AM |
| Updated: | Jan 30 2013 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress Simple History Plugin RSS Feed Information Disclosure Vulnerability
The Simple History plugin for WordPress is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information like activated plugins, new users, and unpublished posts. Information obtained may aid in further attacks.
Simple History 1.0.7 is vulnerable; other versions may also be affected.
The Simple History plugin for WordPress is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information like activated plugins, new users, and unpublished posts. Information obtained may aid in further attacks.
Simple History 1.0.7 is vulnerable; other versions may also be affected.
Exploit / POC
WordPress Simple History Plugin RSS Feed Information Disclosure Vulnerability
Attackers can exploit this issue using a browser.
Attackers can exploit this issue using a browser.
Solution / Fix
WordPress Simple History Plugin RSS Feed Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
WordPress Simple History Plugin RSS Feed Information Disclosure Vulnerability
References:
References:
- WordPress Homepage (WordPress)