JM Twitter Cards [jm-twitter-cards] < 14.1.0 (closed)
unknown
[en] The JM Twitter Cards plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 12 via the meta description data. This makes it possible for unauthenticated attackers to view password protected post content when viewing the page source.
- Affected:
- up to 14.1.0
- Fixed in:
- 14.1.0
- Disclosed:
- Mar 5, 2024
CVE-2024-1769 on NVD →
JM Twitter Cards <= 14 - Information Exposure via Meta Description
medium
The JM Twitter Cards plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 14 via the meta description data. This makes it possible for unauthenticated attackers to view password protected post content when viewing the page source.
- CVSS:
- 5.3
- Affected:
- up to 14
- Fixed in:
- 14.1.0
- Disclosed:
- Mar 4, 2024
CVE-2024-1769 on NVD →
JM Twitter Cards [jm-twitter-cards] < 6.2 (closed)
unknown
Update this plugin.
An unknown person discovered and reported this Full Path Disclosure (FPD) vulnerability in WordPress JM Twitter Cards Plugin. This vulnerability has been fixed in version 6.2.
- Affected:
- up to 6.2
- Fixed in:
- 6.2
- Disclosed:
- Oct 12, 2023
JM Twitter Cards < 6.2 - Full Path Disclosure
high
The JM Twitter Cards plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 6.1 via the esc_html_e function. This can allow unauthenticated attackers to extract sensitive data including the full path of the WordPress installation on the server.
- CVSS:
- 7.5
- Affected:
- up to 6.2
- Fixed in:
- 6.2
- Disclosed:
- Oct 12, 2015
JM Twitter Cards [jm-twitter-cards] < 6.2 (closed)
unknown
Because of this vulnerability, attackers can discover the full path to the WordPress installation on the server, which they could use to assist in other attacks.
Update this plugin.
- Affected:
- up to 6.2
- Fixed in:
- 6.2
- Disclosed:
- Oct 12, 2015
JM Twitter Cards [jm-twitter-cards] < 6.2 (closed)
unknown
The JM Twitter Cards plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 6.1 via the esc_html_e function. This can allow unauthenticated attackers to extract sensitive data including the full path of the WordPress installation on the server.
- Affected:
- up to 6.2
- Fixed in:
- 6.2
- Disclosed:
- Oct 12, 2015
JM Twitter Cards [jm-twitter-cards] < 6.2 (closed)
unknown
The JM Twitter Cards WordPress plugin was affected by a Full Path Disclosure (FPD) security vulnerability.
- Affected:
- up to 6.2
- Fixed in:
- 6.2
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database