{
 "id": "WPSEC-2026-0573",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0573/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0573/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0573/index.md",
 "title": "Parse.ly <= 3.24.1 - Unauthenticated Sensitive Information Exposure of API Secret via Recommended Widget",
 "description": "The Parse.ly plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 3.17.0 up to, and including, 3.24.1. The Parse.ly Recommended Widget builds its Recommendations API URL with a URL builder that adds the site's Parse.ly API Secret, and prints that URL in the widget's markup on the front end. This makes it possible for unauthenticated attackers to obtain the site's Parse.ly API Secret from any page that displays the widget, and use it to access the site's Parse.ly API data.",
 "plugin": {
  "slug": "wp-parsely",
  "name": "Parse.ly",
  "full_name": "Parse.ly",
  "wordpress_org": "https://wordpress.org/plugins/wp-parsely/",
  "advisories_url": "https://wpsec.com/vuln/plugin/wp-parsely/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/wp-parsely"
 },
 "type": "SENSITIVE DATA DISCLOSURE",
 "cwe": [
  "CWE-200"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "3.17.0",
    "from_inclusive": true,
    "to": "3.24.2",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 3.17.0 before 3.24.2"
  ]
 },
 "introduced_in": "3.17.0",
 "fixed_in": "3.24.2",
 "remediation": "Update to 3.24.2 or later.",
 "fix_released": "2026-10-06T15:36:51+00:00",
 "published": "2026-10-07T15:58:04+00:00",
 "updated": "2026-10-06T19:48:15.044008+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0573/",
  "https://plugins.svn.wordpress.org/wp-parsely/tags/3.24.2/",
  "https://wordpress.org/plugins/wp-parsely/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/wp-parsely",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}