The VK All in One Expansion Unit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 9.95.0.1 via social meta tags. This makes it possible for unauthenticated attackers to view limited password protected content.
References
Configurations
History
11 Apr 2025, 13:06
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/vektor-inc/vk-all-in-one-expansion-unit/pull/1072 - Issue Tracking, Vendor Advisory | |
References | () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3050823%40vk-all-in-one-expansion-unit&new=3050823%40vk-all-in-one-expansion-unit&sfp_email=&sfph_mail= - Patch | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/ea2b5dca-42a5-49d4-800d-b268572968a9?source=cve - Third Party Advisory | |
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:a:vektor-inc:vk_all_in_one_expansion_unit:*:*:*:*:*:wordpress:*:* | |
First Time |
Vektor-inc vk All In One Expansion Unit
Vektor-inc |
21 Nov 2024, 09:09
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/vektor-inc/vk-all-in-one-expansion-unit/pull/1072 - | |
References | () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3050823%40vk-all-in-one-expansion-unit&new=3050823%40vk-all-in-one-expansion-unit&sfp_email=&sfph_mail= - | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/ea2b5dca-42a5-49d4-800d-b268572968a9?source=cve - |
09 Apr 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-09 19:15
Updated : 2025-04-11 13:06
NVD link : CVE-2024-2093
Mitre link : CVE-2024-2093
CVE.ORG link : CVE-2024-2093
JSON object : View
Products Affected
vektor-inc
- vk_all_in_one_expansion_unit
CWE