The WP Show Posts plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple AJAX functions in all versions up to, and including, 1.1.5. This makes it possible for authenticated attackers, with subscriber access and above, to view arbitrary post metadata, list posts, and view terms and taxonomies.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-58944 The WP Show Posts plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple AJAX functions in all versions up to, and including, 1.1.5. This makes it possible for authenticated attackers, with subscriber access and above, to view arbitrary post metadata, list posts, and view terms and taxonomies.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 05 Mar 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Generatepress
Generatepress wp Show Posts
Weaknesses CWE-862
CPEs cpe:2.3:a:generatepress:wp_show_posts:*:*:*:*:*:wordpress:*:*
Vendors & Products Generatepress
Generatepress wp Show Posts

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-08-02T08:35:14.907Z

Reserved: 2023-12-12T14:38:12.231Z

Link: CVE-2023-6731

cve-icon Vulnrichment

Updated: 2024-08-02T08:35:14.907Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-02T17:15:08.150

Modified: 2025-03-05T15:11:27.097

Link: CVE-2023-6731

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.