'; } else{ echo ''; } echo 'Hillstone Networks'; } elseif ($_SERVER[HTTP_HOST] == "update1.huaantech.com.cn") { echo ''; echo 'huaantech'; } elseif ($_SERVER[HTTP_HOST] == "update1.dcnetworks.com.cn") { echo ''; echo 'dcnetworks'; } elseif ($_SERVER[HTTP_HOST] == "update1.w-ibeda.com") { if (false===strpos($_SERVER[REQUEST_URI],"/en/")) echo ''; else echo ''; echo 'w-ibeda'; } elseif ($_SERVER[HTTP_HOST] == "update1.hp-telecom.com") { echo ''; echo 'hp-telecom'; } elseif ($_SERVER[HTTP_HOST] == "update1.maipu.com") { echo ''; echo 'Maipu'; } elseif ($_SERVER[HTTP_HOST] == "update1.ncurity.com") { echo ''; echo 'Ncurity'; } elseif ($_SERVER[HTTP_HOST] == "update1.socusnetwork.com") { echo ''; echo 'Socusnetwork'; } else{ echo ''; echo 'Hillstone Networks'; } ?>
 
   
 

RULE(RULE ID:345218)

Rule General Information
Release Date: 2026-07-06
Rule Name: Social Metrics Tracker Unauthorised Data Export Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Social Metrics Tracker WordPress plugin <= 1.6.8 contains an unauthorised data export vulnerability due to lack of proper authorisation when exporting data. Unauthenticated users can access the export endpoint to retrieve information about blog posts and pages, including authors' usernames and email addresses.
Impact: Unauthenticated attackers can retrieve sensitive information about blog posts, pages, and their authors, potentially leading to privacy violations and targeted attacks against blog authors.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.