CVE · Medium

CVE-2022-47160 — Wp Social Login and Register Social Counter [wp-social] < 2.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-47160 Wp Social Login and Register Social Counter [wp-social] < 2.0 Exposure of Sensitive Information to an Unauthorized Actor Medium 6.5 < 2.0 2.0 2022-12-14

CVE-2022-47160

The Wp Social plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.9.0. This is due to missing capability checks on the 'export_users_content_csv' function. This makes it possible for authenticated attackers with minimal permissions such as subscribers to export user content such as user logins and passwords of various social media providers.

Source: Wordfence

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.