Логотип exploitDog
bind:CVE-2023-0453
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-0453

Количество 2

Количество 2

nvd логотип

CVE-2023-0453

почти 3 года назад

The WP Private Message WordPress plugin (bundled with the Superio theme as a required plugin) before 1.0.6 does not ensure that private messages to be accessed belong to the user making the requests. This allowing any authenticated users to access private messages belonging to other users by tampering the ID.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-849q-f682-346f

почти 3 года назад

The WP Private Message WordPress plugin (bundled with the Superio theme as a required plugin) before 1.0.6 does not ensure that private messages to be accessed belong to the user making the requests. This allowing any authenticated users to access private messages belonging to other users by tampering the ID.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-0453

The WP Private Message WordPress plugin (bundled with the Superio theme as a required plugin) before 1.0.6 does not ensure that private messages to be accessed belong to the user making the requests. This allowing any authenticated users to access private messages belonging to other users by tampering the ID.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-849q-f682-346f

The WP Private Message WordPress plugin (bundled with the Superio theme as a required plugin) before 1.0.6 does not ensure that private messages to be accessed belong to the user making the requests. This allowing any authenticated users to access private messages belonging to other users by tampering the ID.

CVSS3: 4.3
0%
Низкий
почти 3 года назад

Уязвимостей на страницу