Описание
The W4 Post List WordPress plugin before 2.4.6 does not ensure that password protected posts can be accessed before displaying their content, which could allow any authenticated users to access them
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.4.6 (исключая)
cpe:2.3:a:w4_post_list_project:w4_post_list:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 51%
0.00278
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-862
Связанные уязвимости
CVSS3: 6.5
github
почти 3 года назад
The W4 Post List WordPress plugin before 2.4.6 does not ensure that password protected posts can be accessed before displaying their content, which could allow any authenticated users to access them
EPSS
Процентиль: 51%
0.00278
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-862