CVE-2023-3706

Severity
4.3MEDIUM
EPSS
0.1%
top 70.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16

Description

The ActivityPub WordPress plugin before 1.0.0 does not ensure that post titles to be displayed are public and belong to the plugin, allowing any authenticated user, such as subscriber to retrieve the title of arbitrary post (such as draft and private) via an IDOR vector

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

CVEListV5unknown/activitypub< 1.0.0

🔴Vulnerability Details

2
GHSA
GHSA-mc66-gqxj-pwmg: The ActivityPub WordPress plugin before 12023-10-16
CVEList
ActivityPub for WordPress < 1.0.0 - Subscriber+ Arbitrary Post Title Disclosure2023-10-16
CVE-2023-3706 (MEDIUM CVSS 4.3) | The ActivityPub WordPress plugin be | cvebase.io