CVE-2024-3678

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.4.2. This makes it possible for unauthenticated attackers to view limited information from password protected posts.
Configurations

Configuration 1 (hide)

cpe:2.3:a:adenion:blog2social:*:*:*:*:*:wordpress:*:*

History

05 Jun 2025, 20:51

Type Values Removed Values Added
References () https://plugins.trac.wordpress.org/changeset/3069574/blog2social/trunk/includes/Meta.php - () https://plugins.trac.wordpress.org/changeset/3069574/blog2social/trunk/includes/Meta.php - Patch
References () https://plugins.trac.wordpress.org/changeset/3074883/blog2social/trunk/includes/Meta.php - () https://plugins.trac.wordpress.org/changeset/3074883/blog2social/trunk/includes/Meta.php - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/2dea1bcb-14c2-4ec9-8a4d-087bac2db486?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/2dea1bcb-14c2-4ec9-8a4d-087bac2db486?source=cve - Third Party Advisory
CPE cpe:2.3:a:adenion:blog2social:*:*:*:*:*:wordpress:*:*
CWE CWE-922
First Time Adenion
Adenion blog2social

21 Nov 2024, 09:30

Type Values Removed Values Added
Summary
  • (es) El complemento Blog2Social: Social Media Auto Post & Scheduler para WordPress es vulnerable a la exposición de información confidencial en todas las versiones hasta la 7.4.2 incluida. Esto hace posible que atacantes no autenticados vean información limitada de publicaciones protegidas con contraseña.
References () https://plugins.trac.wordpress.org/changeset/3069574/blog2social/trunk/includes/Meta.php - () https://plugins.trac.wordpress.org/changeset/3069574/blog2social/trunk/includes/Meta.php -
References () https://plugins.trac.wordpress.org/changeset/3074883/blog2social/trunk/includes/Meta.php - () https://plugins.trac.wordpress.org/changeset/3074883/blog2social/trunk/includes/Meta.php -
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/2dea1bcb-14c2-4ec9-8a4d-087bac2db486?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/2dea1bcb-14c2-4ec9-8a4d-087bac2db486?source=cve -

26 Apr 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-26 08:15

Updated : 2025-06-05 20:51


NVD link : CVE-2024-3678

Mitre link : CVE-2024-3678

CVE.ORG link : CVE-2024-3678


JSON object : View

Products Affected

adenion

  • blog2social
CWE
CWE-922

Insecure Storage of Sensitive Information