CVE-2023-6257
Inline Related Posts < 3.6.0 - Subscriber+ Password Protected Post Read
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Inline Related Posts WordPress plugin before 3.6.0 does not ensure that post content displayed via an AJAX action are accessible to the user, allowing any authenticated user, such as subscriber to retrieve the content of password protected posts
El complemento Inline Related Posts de WordPress anterior a 3.6.0 no garantiza que el contenido de la publicación mostrado mediante una acción AJAX sea accesible para el usuario, lo que permite que cualquier usuario autenticado, como un suscriptor, recupere el contenido de las publicaciones protegidas con contraseña.
The Inline Related Posts WordPress plugin before 3.6.0 is missing authorization in an AJAX action to ensure that users are allowed to see the content of the posts displayed, allowing any authenticated user, such as subscriber to retrieve the content of password protected posts
The Inline Related Posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.0 via the irp_get_list_posts() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve the contents of password protected posts.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-11-22 CVE Reserved
- 2024-03-21 CVE Published
- 2024-04-11 EPSS Updated
- 2024-08-30 CVE Updated
- 2024-08-30 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/19a86448-8d7c-4f02-9290-d9f93810e6e1 | 2024-08-30 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Unknown Search vendor "Unknown" | Inline Related Posts Search vendor "Unknown" for product "Inline Related Posts" | < 3.6.0 Search vendor "Unknown" for product "Inline Related Posts" and version " < 3.6.0" | en |
Affected
|