5.3

CVE-2024-1479

WP Show Posts <= 1.1.4 - Information Exposure

WP Show Posts <= 1.1.4 - Information Exposure

The WP Show Posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 via the wpsp_display function. This makes it possible for authenticated attackers with contributor access and above to view the contents of draft, trash, future, private and pending posts and pages.
Mögliche Gegenmaßnahme
WP Show Posts: Update to version 1.1.5, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GeneratepressWp Show Posts SwPlatformwordpress Version < 1.1.5
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt WP Show Posts
Version *-1.1.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.65% 0.464
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@wordfence.com 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://plugins.trac.wordpress.org/browser/wp-show-posts/trunk/wp-show-posts.php#L224
Product
https://plugins.trac.wordpress.org/browser/wp-show-posts/trunk/wp-show-posts.php#L591
Product
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3041416%40wp-show-posts%2Ftrunk&old=2846296%40wp-show-posts%2Ftrunk&sfp_email=&sfph_mail=
Patch
https://www.wordfence.com/threat-intel/vulnerabilities/id/6788e2ee-ce61-494b-8d7f-6d1144466e58?source=cve
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/6788e2ee-ce61-494b-8d7f-6d1144466e58
Third Party Advisory