5.3

CVE-2023-5561

Exploit

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack

Data is provided by the National Vulnerability Database (NVD)
WordpressWordpress Version >= 4.7 < 4.7.27
WordpressWordpress Version >= 4.8 < 4.8.23
WordpressWordpress Version >= 4.9 < 4.9.24
WordpressWordpress Version >= 5.0 < 5.0.20
WordpressWordpress Version >= 5.1 < 5.1.17
WordpressWordpress Version >= 5.2 < 5.2.19
WordpressWordpress Version >= 5.3 < 5.3.16
WordpressWordpress Version >= 5.4 < 5.4.14
WordpressWordpress Version >= 5.5 < 5.5.13
WordpressWordpress Version >= 5.6 < 5.6.12
WordpressWordpress Version >= 5.7 < 5.7.10
WordpressWordpress Version >= 5.8 < 5.8.8
WordpressWordpress Version >= 5.9 < 5.9.8
WordpressWordpress Version >= 6.0 < 6.0.6
WordpressWordpress Version >= 6.1 < 6.1.4
WordpressWordpress Version >= 6.2 < 6.2.3
WordpressWordpress Version >= 6.3 < 6.3.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 62.78% 0.983
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N