SB2023062822 - Information disclosure in EmbedPress plugin for WordPress
Published: June 28, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use of Hard-coded Cryptographic Key (CVE-ID: CVE-2023-3371)
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a hardcoded encryption key in the "lock_content_form_handler" and "display_password_form" functions. A remote attacker can gain unauthorized access to sensitive information on the system.
Remediation
Install update from vendor's website.
References
- https://plugins.trac.wordpress.org/browser/embedpress/tags/3.7.3/EmbedPress/Includes/Classes/Helper.php#L231
- https://www.wordfence.com/threat-intel/vulnerabilities/id/c1033b4d-82a0-4484-aebf-f35d6a2a9a13?source=cve
- https://plugins.trac.wordpress.org/changeset/2930523/embedpress#file28
- https://plugins.trac.wordpress.org/changeset/2930523/embedpress#file10
- https://plugins.trac.wordpress.org/browser/embedpress/tags/3.7.3/EmbedPress/Includes/Classes/Helper.php#L278
- https://plugins.trac.wordpress.org/browser/embedpress/tags/3.7.3/Gutenberg/block-backend/block-embedpress.php#L30