CVE-2015-0902: Infoleak
The Semper Fi All in One SEO Pack plugin before 2.2.6 for WordPress does not consider the presence of password protection during generation of the Meta Description field, which allows remote attackers to obtain sensitive information by reading HTML source code.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0902?
CVE-2015-0902 is classified as a medium severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2015-0902?
To fix CVE-2015-0902, update the All in One SEO Pack plugin to version 2.2.6 or later.
What vulnerabilities does CVE-2015-0902 expose?
CVE-2015-0902 exposes sensitive information through the Meta Description field when password protection is not considered.
Who is affected by CVE-2015-0902?
Users of the Semper Fi All in One SEO Pack plugin versions prior to 2.2.6 for WordPress are affected by CVE-2015-0902.
What systems are impacted by CVE-2015-0902?
The impacted systems are those running WordPress with the affected versions of the All in One SEO Pack plugin.