Lucene search

K
cvelistWPScanCVELIST:CVE-2023-0453
HistoryFeb 21, 2023 - 8:50 a.m.

CVE-2023-0453 WP Private Message < 1.0.6 - Private Message Disclosure via IDOR

2023-02-2108:50:54
WPScan
www.cve.org
1
wp private message
wordpress plugin
superio theme
private message disclosure
idor
cve-2023-0453

AI Score

4.8

Confidence

High

EPSS

0.001

Percentile

25.5%

The WP Private Message WordPress plugin (bundled with the Superio theme as a required plugin) before 1.0.6 does not ensure that private messages to be accessed belong to the user making the requests. This allowing any authenticated users to access private messages belonging to other users by tampering the ID.

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "WP Private Message",
    "versions": [
      {
        "status": "affected",
        "versionType": "custom",
        "version": "0",
        "lessThan": "1.0.6"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

AI Score

4.8

Confidence

High

EPSS

0.001

Percentile

25.5%

Related for CVELIST:CVE-2023-0453