Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"cveId": "CVE-2023-39999", "assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3", "state": "PUBLISHED", "assignerShortName": "Patchstack", "dateReserved": "2023-08-08T11:43:05.859Z", "datePublished": "2023-10-13T11:31:16.977Z", "dateUpdated": "2025-02-13T17:03:20.665Z"}, "containers": {"cna": {"affected": [{"defaultStatus": "unaffected", "product": "WordPress", "vendor": "WordPress.org", "versions": [{"changes": [{"at": "6.3.2", "status": "unaffected"}], "lessThanOrEqual": "6.3.1", "status": "affected", "version": "6.3", "versionType": "custom"}, {"changes": [{"at": "6.2.3", "status": "unaffected"}], "lessThanOrEqual": "6.2.2", "status": "affected", "version": "6.2", "versionType": "custom"}, {"changes": [{"at": "6.1.4", "status": "unaffected"}], "lessThanOrEqual": "6.13", "status": "affected", "version": "6.1", "versionType": "custom"}, {"changes": [{"at": "6.0.6", "status": "unaffected"}], "lessThanOrEqual": "6.0.5", "status": "affected", "version": "6.0", "versionType": "custom"}, {"changes": [{"at": "5.9.8", "status": "unaffected"}], "lessThanOrEqual": "5.9.7", "status": "affected", "version": "5.9", "versionType": "custom"}, {"changes": [{"at": "5.8.8", "status": "unaffected"}], "lessThanOrEqual": "5.8.7", "status": "affected", "version": "5.8", "versionType": "custom"}, {"changes": [{"at": "5.7.10", "status": "unaffected"}], "lessThanOrEqual": "5.7.9", "status": "affected", "version": "5.7", "versionType": "custom"}, {"changes": [{"at": "5.6.12", "status": "unaffected"}], "lessThanOrEqual": "5.6.11", "status": "affected", "version": "5.6", "versionType": "custom"}, {"changes": [{"at": "5.5.13", "status": "unaffected"}], "lessThanOrEqual": "5.5.12", "status": "affected", "version": "5.5", "versionType": "custom"}, {"changes": [{"at": "5.4.14", "status": "unaffected"}], "lessThanOrEqual": "5.4.13", "status": "affected", "version": "5.4", "versionType": "custom"}, {"changes": [{"at": "5.3.16", "status": "unaffected"}], "lessThanOrEqual": "5.3.15", "status": "affected", "version": "5.3", "versionType": "custom"}, {"changes": [{"at": "5.2.19", "status": "unaffected"}], "lessThanOrEqual": "5.2.18", "status": "affected", "version": "5.2", "versionType": "custom"}, {"changes": [{"at": "5.1.17", "status": "unaffected"}], "lessThanOrEqual": "5.1.16", "status": "affected", "version": "5.1", "versionType": "custom"}, {"changes": [{"at": "5.0.20", "status": "unaffected"}], "lessThanOrEqual": "5.0.19", "status": "affected", "version": "5.0", "versionType": "custom"}, {"changes": [{"at": "4.9.24", "status": "unaffected"}], "lessThanOrEqual": "4.9.23", "status": "affected", "version": "4.9", "versionType": "custom"}, {"changes": [{"at": "4.8.23", "status": "unaffected"}], "lessThanOrEqual": "4.8.22", "status": "affected", "version": "4.8", "versionType": "custom"}, {"changes": [{"at": "4.7.27", "status": "unaffected"}], "lessThanOrEqual": "4.7.26", "status": "affected", "version": "4.7", "versionType": "custom"}, {"changes": [{"at": "4.6.27", "status": "unaffected"}], "lessThanOrEqual": "4.6.26", "status": "affected", "version": "4.6", "versionType": "custom"}, {"changes": [{"at": "4.5.30", "status": "unaffected"}], "lessThanOrEqual": "4.5.29", "status": "affected", "version": "4.5", "versionType": "custom"}, {"changes": [{"at": "4.4.31", "status": "unaffected"}], "lessThanOrEqual": "4.4.30", "status": "affected", "version": "4.4", "versionType": "custom"}, {"changes": [{"at": "4.3.32", "status": "unaffected"}], "lessThanOrEqual": "4.3.31", "status": "affected", "version": "4.3", "versionType": "custom"}, {"changes": [{"at": "4.2.36", "status": "unaffected"}], "lessThanOrEqual": "4.2.35", "status": "affected", "version": "4.2", "versionType": "custom"}, {"changes": [{"at": "4.1.39", "status": "unaffected"}], "lessThanOrEqual": "4.1.38", "status": "affected", "version": "4.1", "versionType": "custom"}]}], "credits": [{"lang": "en", "type": "finder", "user": "00000000-0000-4000-9000-000000000000", "value": "Rafie Muhammad (Patchstack)"}, {"lang": "en", "type": "finder", "user": "00000000-0000-4000-9000-000000000000", "value": "Jb Audras (WordPress Security Team)"}], "datePublic": "2023-10-13T05:00:00.000Z", "descriptions": [{"lang": "en", "supportingMedia": [{"base64": false, "type": "text/html", "value": "Exposure of Sensitive Information to an Unauthorized Actor in WordPress<span style=\"background-color: var(--wht);\"> from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9, from 5.6 through 5.6.11, from 5.5 through 5.5.12, from 5.4 through 5.4.13, from 5.3 through 5.3.15, from 5.2 through 5.2.18, from 5.1 through 5.1.16, from 5.0 through 5.0.19, from 4.9 through 4.9.23, from 4.8 through 4.8.22, from 4.7 through 4.7.26, from 4.6 through 4.6.26, from 4.5 through 4.5.29, from 4.4 through 4.4.30, from 4.3 through 4.3.31, from 4.2 through 4.2.35, from 4.1 through 4.1.38.</span>"}], "value": "Exposure of Sensitive Information to an Unauthorized Actor in WordPress\u00a0from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9, from 5.6 through 5.6.11, from 5.5 through 5.5.12, from 5.4 through 5.4.13, from 5.3 through 5.3.15, from 5.2 through 5.2.18, from 5.1 through 5.1.16, from 5.0 through 5.0.19, from 4.9 through 4.9.23, from 4.8 through 4.8.22, from 4.7 through 4.7.26, from 4.6 through 4.6.26, from 4.5 through 4.5.29, from 4.4 through 4.4.30, from 4.3 through 4.3.31, from 4.2 through 4.2.35, from 4.1 through 4.1.38."}], "impacts": [{"capecId": "CAPEC-1", "descriptions": [{"lang": "en", "value": "CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs"}]}], "metrics": [{"cvssV3_1": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 4.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N", "version": "3.1"}, "format": "CVSS", "scenarios": [{"lang": "en", "value": "GENERAL"}]}], "problemTypes": [{"descriptions": [{"cweId": "CWE-200", "description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor", "lang": "en", "type": "CWE"}]}], "providerMetadata": {"orgId": "21595511-bba5-4825-b968-b78d1f9984a3", "shortName": "Patchstack", "dateUpdated": "2023-11-20T23:06:12.283Z"}, "references": [{"tags": ["third-party-advisory"], "url": "https://patchstack.com/articles/wordpress-core-6-3-2-security-update-technical-advisory?_s_id=cve"}, {"tags": ["vdb-entry"], "url": "https://patchstack.com/database/vulnerability/wordpress/wordpress-wordpress-core-core-6-3-2-contributor-comment-read-on-private-and-password-protected-post-vulnerability?_s_id=cve"}, {"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2EVFT4DPZRFTXJPEPADM22BZVIUD2P66/"}, {"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WQBL4ZQCBFNQ76XHM5257CIBFQRGT5QY/"}, {"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GCCVDPKOK57WCTH2QJ5DJM3B53RJNZKA/"}, {"url": "https://lists.debian.org/debian-lts-announce/2023/11/msg00014.html"}], "solutions": [{"lang": "en", "supportingMedia": [{"base64": false, "type": "text/html", "value": "Update to suitable (6.3.2, 6.2.3, 6.1.4, 6.0.6, 5.9.8, 5.8.8, 5.7.10, 5.6.12, 5.5.13, 5.4.14, 5.3.16, 5.2.19, 5.1.17, 5.0.20, 4.9.24, 4.8.23, 4.7.27, 4.6.27, 4.5.30, 4.4.31, 4.3.32, 4.2.36, 4.1.39) or a higher version."}], "value": "Update to suitable (6.3.2,\u00a06.2.3, 6.1.4, 6.0.6, 5.9.8, 5.8.8, 5.7.10, 5.6.12, 5.5.13, 5.4.14, 5.3.16, 5.2.19, 5.1.17, 5.0.20, 4.9.24, 4.8.23, 4.7.27, 4.6.27, 4.5.30, 4.4.31, 4.3.32, 4.2.36, 4.1.39) or a higher version."}], "source": {"discovery": "EXTERNAL"}, "title": "WordPress < 6.3.2 is vulnerable to Broken Access Control", "x_generator": {"engine": "Vulnogram 0.1.0-dev"}}, "adp": [{"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-02T18:18:10.210Z"}, "title": "CVE Program Container", "references": [{"tags": ["third-party-advisory", "x_transferred"], "url": "https://patchstack.com/articles/wordpress-core-6-3-2-security-update-technical-advisory?_s_id=cve"}, {"tags": ["vdb-entry", "x_transferred"], "url": "https://patchstack.com/database/vulnerability/wordpress/wordpress-wordpress-core-core-6-3-2-contributor-comment-read-on-private-and-password-protected-post-vulnerability?_s_id=cve"}, {"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2EVFT4DPZRFTXJPEPADM22BZVIUD2P66/", "tags": ["x_transferred"]}, {"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WQBL4ZQCBFNQ76XHM5257CIBFQRGT5QY/", "tags": ["x_transferred"]}, {"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GCCVDPKOK57WCTH2QJ5DJM3B53RJNZKA/", "tags": ["x_transferred"]}, {"url": "https://lists.debian.org/debian-lts-announce/2023/11/msg00014.html", "tags": ["x_transferred"]}]}]}}