CVE-2024-2088
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.3 via the 'nxs_getExpSettings' function. This makes it possible for authenticated attackers, with subscriber access and above, to extract sensitive data including social network API keys and secrets.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
- EPSS probability
- 0.34%
- CWE
- CWE-202
- Published
- 2024-05-22
- Last modified
- 2026-04-09
Affected products
- nextscripts NextScripts: Social Networks Auto-Poster
- nextscripts NextScripts: Social Networks Auto-Poster
Weakness type
Related vulnerabilities
- CVE-2021-32743 — Passwords used to access external services inadvertently exposed through API
- CVE-2025-25205 — Remote Authentication-Bypass can lead to server crash or limited information disclosure due to faulty pattern matching
- CVE-2026-33530 — InvenTree Vulnerable to ORM Filter Injection
- CVE-2025-69200 — phpMyFAQ has unauthenticated config backup download via /api/setup/backup
- CVE-2025-36575 — Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Exposure of Sensitive Information Through Data Queries
- CVE-2025-29981 — Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Exposure of Sensitive Information Through Data Querie
- CVE-2023-1625 — Information leak in api
- CVE-2026-16520 — Improper input validation and Exposure of sensitive information through data queries vulnerability in Genians Genian NAC