668
VMScore

CVE-2018-20555

Published: 21/03/2019 Updated: 16/04/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote malicious users to discover Twitter access_token, access_token_secret, consumer_key, and consumer_secret values by reading the dcwp_twitter.php source code. This leads to Twitter account takeover.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

designchemical social network tabs 1.7.1

Github Repositories

Social Network Tabs Wordpress Plugin Vulnerability - CVE-2018-20555

CVE-2018-20555 The Wordpress Plugin called Social Network Tabs, made by the company Design Chemical, is leaking twice the Twitter access_token, access_token_secret, consumer_key and consumer_secret of their user which is leading to a takeover of their Twitter account This is caused by the following lines of code within the page where the Twitter widget is displayed: jQuery(doc