'; } else{ echo ''; } echo '
|
|
|||
| Rule General Information |
|---|
| Release Date: | 2026-07-06 | |
| Rule Name: | Social Metrics Tracker Unauthorised Data Export Vulnerability | |
| Severity: | ||
| CVE ID: | ||
| Rule Protection Details |
|---|
| Description: | Social Metrics Tracker WordPress plugin <= 1.6.8 contains an unauthorised data export vulnerability due to lack of proper authorisation when exporting data. Unauthenticated users can access the export endpoint to retrieve information about blog posts and pages, including authors' usernames and email addresses. | |
| Impact: | Unauthenticated attackers can retrieve sensitive information about blog posts, pages, and their authors, potentially leading to privacy violations and targeted attacks against blog authors. | |
| Affected OS: | Windows, Linux, Others | |
| Reference: | ||
| Solutions |
|---|
| Please contact the software vendor to update the software patch. |