4.3
CVE-2024-1204
- EPSS 0.5%
- Veröffentlicht 15.04.2024 05:15:14
- Zuletzt bearbeitet 15.05.2025 13:40:27
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Meta Box < 5.9.4 - Contributor+ Arbitrary Posts' Custom Field Disclosure
Meta Box – WordPress Custom Fields Framework <= 5.9.3 - Authenticated (Contributor+) Information Exposure via Post Meta
The Meta Box WordPress plugin before 5.9.4 does not prevent users with at least the contributor role from access arbitrary custom fields assigned to other user's posts.
Mögliche Gegenmaßnahme
Meta Box: Update to version 5.9.4, or a newer patched version
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.5% | 0.388 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
https://wpscan.com/vulnerability/03191b00-0b05-42db-9ce2-fc525981b6c9/
https://www.wordfence.com/threat-intel/vulnerabilities/id/6276a405-4879-4429-8fc1-2d567ded5112