Sensitive Information Exposure in Ad Inserter for WordPress
CVE-2023-4668

5.3MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
20 October 2023

Summary

The Ad Inserter plugin for WordPress, up to version 2.7.30, is susceptible to a Sensitive Information Exposure vulnerability. This flaw can be exploited via the ai-debug-processing-fe URL parameter, allowing unauthorized users to access sensitive data such as active plugins, themes, various plugin settings, and certain server configurations like memory limits and installation paths. Proper mitigation is essential to prevent unauthorized data access.

Affected Version(s)

Ad Inserter – Ad Manager & AdSense Ads * <= 2.7.30

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marco Wotschka
.