Vulnerabilities / Parse.ly / WPSEC-2026-0573

Parse.ly <= 3.24.1 - Unauthenticated Sensitive Information Exposure of API Secret via Recommended Widget

Medium 5.3 CWE-200Fixed in 3.24.2
ID
WPSEC-2026-0573
Plugin
Parse.ly (wp-parsely)
Affected
from 3.17.0 before 3.24.2
Remediation
Update to 3.24.2 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-200
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
Parse.ly on WPSec AttackSurface
Fix released
Published

Description

The Parse.ly plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 3.17.0 up to, and including, 3.24.1. The Parse.ly Recommended Widget builds its Recommendations API URL with a URL builder that adds the site's Parse.ly API Secret, and prints that URL in the widget's markup on the front end. This makes it possible for unauthenticated attackers to obtain the site's Parse.ly API Secret from any page that displays the widget, and use it to access the site's Parse.ly API data.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0