Sensitive Information Exposure in Ad Inserter for WordPress
CVE-2023-4668
5.3MEDIUM
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 20 October 2023
Summary
The Ad Inserter plugin for WordPress, up to version 2.7.30, is susceptible to a Sensitive Information Exposure vulnerability. This flaw can be exploited via the ai-debug-processing-fe URL parameter, allowing unauthorized users to access sensitive data such as active plugins, themes, various plugin settings, and certain server configurations like memory limits and installation paths. Proper mitigation is essential to prevent unauthorized data access.
Affected Version(s)
Ad Inserter – Ad Manager & AdSense Ads * <= 2.7.30
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Marco Wotschka