CVE-2023-4036
Simple Blog Card < 1.32 - Subscriber+ Arbitrary Post Access
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Simple Blog Card WordPress plugin before 1.32 does not ensure that posts to be displayed via a shortcode are public, allowing any authenticated users, such as subscriber, to retrieve arbitrary post title and their content such as draft, private and password protected ones
El plugin Simple Blog Card WordPress anterior a la versión 1.32 no garantiza que las entradas que se muestren a través de un shortcode sean públicas, lo que permite a cualquier usuario autenticado, como el suscriptor, recuperar cualquier título de entrada y su contenido, como borradores, entradas privadas y protegidas por contraseña.
The Simple Blog Card plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.31 via the 'simpleblogcard' function. This can allow authenticated subscriber-level attackers to extract sensitive data including unpublished or password-protected blog posts.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-08-01 CVE Reserved
- 2023-08-03 CVE Published
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- 2024-09-05 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/de3e1718-c358-4510-b142-32896ffeb03f | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Riverforest-wp Search vendor "Riverforest-wp" | Simple Blog Card Search vendor "Riverforest-wp" for product "Simple Blog Card" | < 1.32 Search vendor "Riverforest-wp" for product "Simple Blog Card" and version " < 1.32" | wordpress |
Affected
|