Skip to content

Sensitive Data: Social Metrics Tracker \<= 1.6.8 - Unauthorised Data Export

Identifier: wordpress_social_metrics_tracker

Scanner(s) Support

GraphQL Scanner REST Scanner WebApp Scanner ASM Scanner

Description

The lack of proper authorisation when exporting data from the plugin could allow unauthenticated users to get information about the posts and page of the blog, including their author's username and email.

Reference:

Configuration

Example

Example configuration:

---
security_tests:
  wordpress_social_metrics_tracker:
    skip: false

Reference

skip

Type : boolean

Skip the test if true.