The wp-schema-pro WordPress plugin before 2.7.16 does not validate post access allowing a contributor user to access custom fields on any post regardless of post type or status via a shortcode
History

Fri, 27 Jun 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Brainstormforce
Brainstormforce schema
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:brainstormforce:schema:*:*:*:*:pro:wordpress:*:*
Vendors & Products Brainstormforce
Brainstormforce schema

Fri, 09 Aug 2024 22:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-03-25T05:00:01.620Z

Updated: 2024-08-09T20:21:19.739Z

Reserved: 2024-02-15T19:53:02.215Z

Link: CVE-2024-1564

cve-icon Vulnrichment

Updated: 2024-08-01T18:40:21.441Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-25T05:15:50.557

Modified: 2025-06-27T15:31:56.910

Link: CVE-2024-1564

cve-icon Redhat

No data.