The Simple Blog Card WordPress plugin before 1.32 does not ensure that posts to be displayed via a shortcode are public, allowing any authenticated users, such as subscriber, to retrieve arbitrary post title and their content such as draft, private and password protected ones
History

Fri, 02 May 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2023-08-30T14:22:01.184Z

Updated: 2025-05-02T15:47:12.758Z

Reserved: 2023-08-01T08:05:12.025Z

Link: CVE-2023-4036

cve-icon Vulnrichment

Updated: 2024-08-02T07:17:11.721Z

cve-icon NVD

Status : Modified

Published: 2023-08-30T15:15:09.813

Modified: 2025-05-02T16:15:22.460

Link: CVE-2023-4036

cve-icon Redhat

No data.