CVE-2023-1371

The W4 Post List WordPress plugin before 2.4.6 does not ensure that password protected posts can be accessed before displaying their content, which could allow any authenticated users to access them
Configurations

Configuration 1 (hide)

cpe:2.3:a:w4_post_list_project:w4_post_list:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 07:39

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/ad5c167e-77f7-453c-9443-df6e07705d89 - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/ad5c167e-77f7-453c-9443-df6e07705d89 - Exploit, Third Party Advisory

21 Apr 2023, 01:28

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-17 13:15

Updated : 2024-11-21 07:39


NVD link : CVE-2023-1371

Mitre link : CVE-2023-1371

CVE.ORG link : CVE-2023-1371


JSON object : View

Products Affected

w4_post_list_project

  • w4_post_list
CWE
CWE-862

Missing Authorization