Логотип exploitDog
bind:CVE-2023-1426
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-1426

Количество 2

Количество 2

nvd логотип

CVE-2023-1426

почти 3 года назад

The WP Tiles WordPress plugin through 1.1.2 does not ensure that posts to be displayed are not draft/private, allowing any authenticated users, such as subscriber to retrieve the titles of draft and privates posts for example. AN attacker could also retrieve the title of any other type of post.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-67rc-9g3p-jjqp

почти 3 года назад

The WP Tiles WordPress plugin through 1.1.2 does not ensure that posts to be displayed are not draft/private, allowing any authenticated users, such as subscriber to retrieve the titles of draft and privates posts for example. AN attacker could also retrieve the title of any other type of post.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-1426

The WP Tiles WordPress plugin through 1.1.2 does not ensure that posts to be displayed are not draft/private, allowing any authenticated users, such as subscriber to retrieve the titles of draft and privates posts for example. AN attacker could also retrieve the title of any other type of post.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-67rc-9g3p-jjqp

The WP Tiles WordPress plugin through 1.1.2 does not ensure that posts to be displayed are not draft/private, allowing any authenticated users, such as subscriber to retrieve the titles of draft and privates posts for example. AN attacker could also retrieve the title of any other type of post.

CVSS3: 6.5
0%
Низкий
почти 3 года назад

Уязвимостей на страницу