The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai-debug-processing-fe URL parameter. This can allow unauthenticated attackers to extract sensitive data including installed plugins (present and active), active theme, various plugin settings, WordPress version, as well as some server settings such as memory limit, installation paths.
                
            References
                    Configurations
                    History
                    No history.
Information
                Published : 2023-10-20 08:15
Updated : 2024-11-21 08:35
NVD link : CVE-2023-4668
Mitre link : CVE-2023-4668
CVE.ORG link : CVE-2023-4668
JSON object : View
Products Affected
                ad_inserter_project
- ad_inserter
CWE
                
                    
                        
                        CWE-862
                        
            Missing Authorization
