User Access Manager < 2.3.15 - Unauthenticated Restricted Content Disclosure via REST API
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.3epss 0.2%
exploitation probability
0.2%top 88% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allowing unauthenticated attackers to read the content of posts, pages and custom post types that have been restricted to specific user groups.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
Unknown · User Access Managerpublic PoCs found — 1
cve_referencewpscan.com/vulnerability/9c5cae62-4c4c-434b-ae40-4654b257803f/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.