CVE-2023-1371

The W4 Post List WordPress plugin before 2.4.6 does not ensure that password protected posts can be accessed before displaying their content, which could allow any authenticated users to access them
Configurations

Configuration 1 (hide)

cpe:2.3:a:w4_post_list_project:w4_post_list:*:*:*:*:*:wordpress:*:*

History

06 Feb 2025, 16:15

Type Values Removed Values Added
CWE CWE-862
References (MISC) https://wpscan.com/vulnerability/ad5c167e-77f7-453c-9443-df6e07705d89 - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/ad5c167e-77f7-453c-9443-df6e07705d89 - Exploit, Third Party Advisory

07 Nov 2023, 04:03

Type Values Removed Values Added
CWE CWE-862

21 Apr 2023, 01:28

Type Values Removed Values Added
CWE CWE-200 CWE-862
First Time W4 Post List Project w4 Post List
W4 Post List Project
CPE cpe:2.3:a:w4_post_list_project:w4_post_list:*:*:*:*:*:wordpress:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References (MISC) https://wpscan.com/vulnerability/ad5c167e-77f7-453c-9443-df6e07705d89 - (MISC) https://wpscan.com/vulnerability/ad5c167e-77f7-453c-9443-df6e07705d89 - Exploit, Third Party Advisory

17 Apr 2023, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-17 13:15

Updated : 2025-02-06 16:15


NVD link : CVE-2023-1371

Mitre link : CVE-2023-1371


JSON object : View

Products Affected

w4_post_list_project

  • w4_post_list
CWE
CWE-862

Missing Authorization