Lucene search

K
nvd[email protected]NVD:CVE-2024-1564
HistoryMar 25, 2024 - 5:15 a.m.

CVE-2024-1564

2024-03-2505:15:50
web.nvd.nist.gov
1
wordpress
plugin
security
access
custom fields
shortcode

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

6.4

Confidence

High

EPSS

0

Percentile

9.0%

The wp-schema-pro WordPress plugin before 2.7.16 does not validate post access allowing a contributor user to access custom fields on any post regardless of post type or status via a shortcode

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

6.4

Confidence

High

EPSS

0

Percentile

9.0%