Description
The Front End PM WordPress plugin before 11.4.3 does not block listing the contents of the directories where it stores attachments to private messages, allowing unauthenticated visitors to list and download private attachments if the autoindex feature of the web server is enabled.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54766 | The Front End PM WordPress plugin before 11.4.3 does not block listing the contents of the directories where it stores attachments to private messages, allowing unauthenticated visitors to list and download private attachments if the autoindex feature of the web server is enabled. |
References
History
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-02-26T21:21:14.187Z
Reserved: 2023-09-13T10:38:08.439Z
Link: CVE-2023-4930
Updated: 2024-08-02T07:44:53.342Z
Status : Modified
Published: 2023-11-06T21:15:09.233
Modified: 2025-02-26T22:15:12.833
Link: CVE-2023-4930
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD