Логотип exploitDog
bind:CVE-2023-5561
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-5561

Количество 5

Количество 5

ubuntu логотип

CVE-2023-5561

больше 2 лет назад

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack

CVSS3: 5.3
EPSS: Средний
nvd логотип

CVE-2023-5561

больше 2 лет назад

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack

CVSS3: 5.3
EPSS: Средний
debian логотип

CVE-2023-5561

больше 2 лет назад

WordPress does not properly restrict which user fields are searchable ...

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-x7w6-3cp2-qjcv

больше 2 лет назад

The Popup Builder WordPress plugin through 4.1.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 5.3
EPSS: Средний
fstec логотип

BDU:2023-08227

больше 2 лет назад

Уязвимость реализации прикладного программного интерфейса системы управления содержимым сайта WordPress, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-5561

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack

CVSS3: 5.3
53%
Средний
больше 2 лет назад
nvd логотип
CVE-2023-5561

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack

CVSS3: 5.3
53%
Средний
больше 2 лет назад
debian логотип
CVE-2023-5561

WordPress does not properly restrict which user fields are searchable ...

CVSS3: 5.3
53%
Средний
больше 2 лет назад
github логотип
GHSA-x7w6-3cp2-qjcv

The Popup Builder WordPress plugin through 4.1.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 5.3
53%
Средний
больше 2 лет назад
fstec логотип
BDU:2023-08227

Уязвимость реализации прикладного программного интерфейса системы управления содержимым сайта WordPress, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.3
53%
Средний
больше 2 лет назад

Уязвимостей на страницу