Lucene search

K
wpexploitScott Kingsley ClarkWPEX-ID:ECB1E36F-9C6E-4754-8878-03C97194644D
HistoryMar 04, 2024 - 12:00 a.m.

Schema Pro < 2.7.16 - Contributor+ Custom Field Access

2024-03-0400:00:00
Scott Kingsley Clark
47
schema pro
contributor
custom field access
post meta key

AI Score

9.5

Confidence

High

EPSS

0

Percentile

9.0%

Description The plugin does not validate post access allowing a contributor user to access custom fields on any post regardless of post type or status via a shortcode

As a contributor, add/edit a post and embed `[aiosrs_pro_custom_field post_id="ANY_POST_ID" field_key="ANY_META_KEY"]` and specify/guess any post ID and meta key you may want to access

Save the post and preview it to disclose the post meta key value

AI Score

9.5

Confidence

High

EPSS

0

Percentile

9.0%

Related for WPEX-ID:ECB1E36F-9C6E-4754-8878-03C97194644D