CVE-2024-1526
MEDIUMCVSS 5.3/10EPSS 0.52%
Last modified
CVE-2024-1526 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The Hubbub Lite WordPress plugin before 1.33.1 does not ensure that user have access to password protected post before displaying its content in a meta tag.. EPSS estimates a 0.52% chance of exploitation in the next 30 days.
Description
The Hubbub Lite WordPress plugin before 1.33.1 does not ensure that user have access to password protected post before displaying its content in a meta tag.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Devpups | Social Pug | < 1.33.1 |
References
- https://wpscan.com/vulnerability/1664697e-0ea3-4d09-b2fd-153a104ec255/Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/1664697e-0ea3-4d09-b2fd-153a104ec255/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-1526?
The Hubbub Lite WordPress plugin before 1.33.1 does not ensure that user have access to password protected post before displaying its content in a meta tag.
How severe is CVE-2024-1526?
CVE-2024-1526 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 0.52% probability of exploitation in the next 30 days.
How do I fix CVE-2024-1526?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-1520An OS Command Injection vulnerability exists in the '/open_c…9.8
- CVE-2024-1521The Elementor Website Builder Pro plugin for WordPress is vu…5.4
- CVE-2024-1522A Cross-Site Request Forgery (CSRF) vulnerability in the par…8.8
- CVE-2024-1523EC-WEB FS-EZViewer(Web)'s query functionality lacks proper r…8.8
- CVE-2024-1524When the "Silent Just-In-Time Provisioning" feature is enabl…8.1
- CVE-2024-1525An issue has been discovered in GitLab CE/EE affecting all v…5.3
- CVE-2024-1527Unrestricted file upload vulnerability in CMS Made Simple, a…8.8
- CVE-2024-1528CMS Made Simple version 2.2.14, does not sufficiently encode…6.1
- CVE-2024-1529Vulnerability in CMS Made Simple 2.2.14, which does not suff…6.1
- CVE-2024-1530A vulnerability, which was classified as critical, has been …8.8
- CVE-2024-1531A vulnerability exists in the stb-language file handling tha…8.2
- CVE-2024-1532A vulnerability exists in the stb-language file handling tha…6.8
Are you affected by CVE-2024-1526?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
