CVE-2024-3678

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.4.2. This makes it possible for unauthenticated attackers to view limited information from password protected posts.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:adenion:blog2social:*:*:*:*:*:wordpress:*:*

History

05 Jun 2025, 20:51

Type Values Removed Values Added
CWE CWE-922
CPE cpe:2.3:a:adenion:blog2social:*:*:*:*:*:wordpress:*:*
First Time Adenion
Adenion blog2social
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/2dea1bcb-14c2-4ec9-8a4d-087bac2db486?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/2dea1bcb-14c2-4ec9-8a4d-087bac2db486?source=cve - Third Party Advisory
References () https://plugins.trac.wordpress.org/changeset/3069574/blog2social/trunk/includes/Meta.php - () https://plugins.trac.wordpress.org/changeset/3069574/blog2social/trunk/includes/Meta.php - Patch
References () https://plugins.trac.wordpress.org/changeset/3074883/blog2social/trunk/includes/Meta.php - () https://plugins.trac.wordpress.org/changeset/3074883/blog2social/trunk/includes/Meta.php - Patch

26 Apr 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-26 08:15

Updated : 2025-06-05 20:51


NVD link : CVE-2024-3678

Mitre link : CVE-2024-3678


JSON object : View

Products Affected

adenion

  • blog2social
CWE
CWE-922

Insecure Storage of Sensitive Information