CVE-2023-5561: medium-severity vulnerability in WordPress
WordPress < 6.3.2 - Unauthenticated Post Author Email Disclosure
Published · Updated
28Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 5.3epss 3.9%
exploitation probability
3.9%top 10% of all CVEs
observed exploitation
nono source reports it
WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
WordPress · WordPressRelated CVEs — WordPress
In the same product, most dangerous first.
CVE-2026-87902HIGHCVE-2026-87902EPSS 46.1%KEVCVE-2026-63030CRITICALWordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code ExecutionEPSS 10.1%KEVCVE-2026-60137MEDIUMWordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_QueryEPSS 5.9%KEVCVE-2020-11027MEDIUMPassword reset links invalidation issue in WordPressEPSS 13.6%CVE-2022-3590MEDIUMWP <= 6.1.1 - Unauthenticated Blind SSRF via DNS RebindingEPSS 3.2%CVE-2020-11028MEDIUMUnauthenticated disclosure of certain private posts in WordPressEPSS 2.3%