CVE-2023-1371Missing Authorization in Post List Project W4 Post List

Severity
6.5MEDIUMNVD
EPSS
0.3%
top 47.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 17

Description

The W4 Post List WordPress plugin before 2.4.6 does not ensure that password protected posts can be accessed before displaying their content, which could allow any authenticated users to access them

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

🔴Vulnerability Details

2
CVEList
W4 Post List < 2.4.6 - Subscriber+ Password Protected Post Content Disclosure2023-04-17
GHSA
GHSA-f99f-842c-6wrr: The W4 Post List WordPress plugin before 22023-04-17
CVE-2023-1371 — Missing Authorization | cvebase