Lucene search

K
cveWPScanCVE-2024-1564
HistoryMar 25, 2024 - 5:15 a.m.

CVE-2024-1564

2024-03-2505:15:50
WPScan
web.nvd.nist.gov
48
wordpress plugin
access control
vulnerability
custom fields
shortcode

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

9.2

Confidence

High

EPSS

0

Percentile

9.0%

The wp-schema-pro WordPress plugin before 2.7.16 does not validate post access allowing a contributor user to access custom fields on any post regardless of post type or status via a shortcode

Affected configurations

Vulners
Vulnrichment
Node
brainstormforceschema_proRange<2.7.16wordpress
VendorProductVersionCPE
brainstormforceschema_pro*cpe:2.3:a:brainstormforce:schema_pro:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "wp-schema-pro",
    "versions": [
      {
        "status": "affected",
        "versionType": "semver",
        "version": "0",
        "lessThan": "2.7.16"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

9.2

Confidence

High

EPSS

0

Percentile

9.0%