Vulnerable Systems:
*Simple History Plugin for WordPress 1.0.7
Simple History Plugin for WordPress contains a flaw that may lead to unauthorized disclosure of potentially sensitive information. The issue is due to the rss_secret being displayed within the source of the RSS feed. This may allow a remote attacker that should not have access to the feed to gain access to unpublished posts, plugin deployment, or new user information.
Disclosure Timeline:
Disclosure Date :2013-01-25
Vendor Solution Date :2013-01-25