CVE-2014-125093 MEDIUM

CVE-2014-125093: Ad Blocking Detector Plugin ad-blocking-detector.php information disclosure

Vendor N/A
Product Ad Blocking Detector Plugin
Weakness CWE-200 · Info exposure
Published March 10, 2023
Last update August 6, 2024

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

A vulnerability has been found in Ad Blocking Detector Plugin up to 1.2.1 on WordPress and classified as problematic. This vulnerability affects unknown code of the file ad-blocking-detector.php. The manipulation leads to information disclosure. The attack can be initiated remotely. Upgrading to version 1.2.2 is able to address this issue. The patch is identified as 3312b9cd79e5710d1e282fc9216a4e5ab31b3d94. It is recommended to upgrade the affected component. VDB-222610 is the identifier assigned to this vulnerability.

Explanation of Vulnerability in Simple Terms

02Summary

The Ad Blocking Detector Plugin contains an information exposure vulnerability that allows authenticated users to access sensitive data they should not be able to view. An attacker with low-level account privileges can read information that is restricted to higher-privilege users. The vulnerability requires network access and valid login credentials but no additional user interaction.

What an attacker can do

03Attacker Capabilities

Read sensitive information restricted to higher-privilege users.

Potential impact on your site

04Site Impact

Authenticated users can view data they should not have access to, potentially exposing private site information.

Conditions required to exploit

05Prerequisites

Valid login account with low-level privileges; network access to the site.

Key dates

06Disclosure timeline

March 10, 2023 CVE published
August 6, 2024 Record updated

Related vulnerabilities

08Related CVE