Easy Custom Auto Excerpt <= 2.4.12 - Sensitive Information Exposure
medium
The Easy Custom Auto Excerpt plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.12. This makes it possible for unauthenticated attackers to obtain excerpts of password-protected posts.
- CVSS:
- 5.3
- Affected:
- up to 2.4.12
- Fixed in:
- 2.5.0
- Disclosed:
- Apr 18, 2024
CVE-2024-3312 on NVD →
Easy Custom Auto Excerpt < 2.4.7 - Stored Cross-Site Scripting
medium
The Easy Custom Auto Excerpt plugin 2.4.6 for WordPress has XSS via the tonjoo_ecae_options[custom_css] parameter to the wp-admin/admin.php?page=tonjoo_excerpt URI.
- CVSS:
- 5.4
- Affected:
- up to 2.4.7
- Fixed in:
- 2.4.7
- Disclosed:
- Nov 13, 2018
CVE-2018-5311 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database