Description
The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are already public and can be viewed, allowing any authenticated users, such as subscriber to access draft posts for example
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-24099 | The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are already public and can be viewed, allowing any authenticated users, such as subscriber to access draft posts for example |
References
History
Thu, 30 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-639 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-01-30T14:29:36.680Z
Reserved: 2023-04-06T14:09:27.448Z
Link: CVE-2023-1911
Updated: 2024-08-02T06:05:26.771Z
Status : Modified
Published: 2023-05-02T08:15:10.570
Modified: 2025-01-30T15:15:14.617
Link: CVE-2023-1911
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD