The BestWebSoft's Like & Share WordPress plugin before 2.74 discloses the content of password protected posts to unauthenticated users via a meta tag
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/6cad602b-7414-4867-8ae2-f0b846c4c8f0 | third party advisory vdb entry exploit technical description |