CVE-2024-3678: Blog2Social: Social Media Auto Post & Scheduler <= 7.4.2 - Information Exposure
Published Apr 26, 2024
·Updated
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.4.2. This makes it possible for unauthenticated attackers to view limited information from password protected posts.
Affected Software
2 affected components
Adenion Blog2social Wordpress<7.5.0
Blog2Social WordPress plugin<=7.4.2
Remediation
Event History
Apr 26, 2024
CVE Published
via MITRE·07:28 AM
Data Sourced
via MITRE·07:28 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-3678?
CVE-2024-3678 is classified as a sensitive information exposure vulnerability.
2
How do I fix CVE-2024-3678?
To fix CVE-2024-3678, update the Blog2Social plugin to version 7.4.3 or later.
3
Who is affected by CVE-2024-3678?
CVE-2024-3678 affects all versions of the Blog2Social plugin for WordPress up to and including version 7.4.2.
4
What kind of information can be exposed due to CVE-2024-3678?
CVE-2024-3678 allows unauthenticated attackers to view limited information from password-protected posts.
5
Are there any known exploits for CVE-2024-3678?
As of now, there are no public exploits specifically targeting CVE-2024-3678 reported.