Open Graph <= 1.11.2 - Unauthenticated Sensitive Information Exposure
mediumThe Open Graph plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.11.2 via the 'opengraph_default_description' function. This makes it possible for unauthenticated attackers to extract sensitive data including partial content of password-protected blog posts.
- CVSS:
- 5.3
- Affected:
- up to 1.11.2
- Fixed in:
- 1.11.3
- Disclosed:
- Jun 4, 2024