← voltar
CVE-2023-6257medium

Inline Related Posts < 3.6.0 - Subscriber+ Password Protected Post Read

13Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 4.3epss 0.5%
probabilidade de exploração
0.5%top 63% das CVEs
exploração observada
nãonenhuma fonte reporta
The Inline Related Posts WordPress plugin before 3.6.0 is missing authorization in an AJAX action to ensure that users are allowed to see the content of the posts displayed, allowing any authenticated user, such as subscriber to retrieve the content of password protected posts
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N