The WP Tiles WordPress plugin through 1.1.2 does not ensure that posts to be displayed are not draft/private, allowing any authenticated users, such as subscriber to retrieve the titles of draft and privates posts for example. AN attacker could also retrieve the title of any other type of post.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/fdd79bb4-d434-4635-bb2b-84d079ecc746 | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/fdd79bb4-d434-4635-bb2b-84d079ecc746 | Exploit Third Party Advisory |
Configurations
History
11 Feb 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://wpscan.com/vulnerability/fdd79bb4-d434-4635-bb2b-84d079ecc746 - Exploit, Third Party Advisory |
14 Apr 2023, 03:14
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:a:keetrax:wp_tiles:*:*:*:*:*:wordpress:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
References | (MISC) https://wpscan.com/vulnerability/fdd79bb4-d434-4635-bb2b-84d079ecc746 - Exploit, Third Party Advisory | |
First Time |
Keetrax
Keetrax wp Tiles |
10 Apr 2023, 14:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-04-10 14:15
Updated : 2025-02-11 22:15
NVD link : CVE-2023-1426
Mitre link : CVE-2023-1426
JSON object : View
Products Affected
keetrax
- wp_tiles
CWE