Lucene search

K
cvelistWPScanCVELIST:CVE-2023-1371
HistoryApr 17, 2023 - 12:17 p.m.

CVE-2023-1371 W4 Post List < 2.4.6 - Subscriber+ Password Protected Post Content Disclosure

2023-04-1712:17:47
WPScan
www.cve.org
3
wordpress
plugin
vulnerability
password protection
disclosure

EPSS

0.001

Percentile

29.8%

The W4 Post List WordPress plugin before 2.4.6 does not ensure that password protected posts can be accessed before displaying their content, which could allow any authenticated users to access them

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "W4 Post List",
    "versions": [
      {
        "status": "affected",
        "versionType": "custom",
        "version": "0",
        "lessThan": "2.4.6"
      }
    ],
    "defaultStatus": "unaffected",
    "collectionURL": "https://wordpress.org/plugins"
  }
]

EPSS

0.001

Percentile

29.8%

Related for CVELIST:CVE-2023-1371