The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthenticated user to read draft and private posts via a crafted request
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/0c96a128-4473-41f5-82ce-94bba33ca4a3/ | Exploit Third Party Advisory |
https://www.relevanssi.com/release-notes/premium-2-25-free-4-22-release-notes/ | Patch |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: WPScan
Published: 2024-01-29T14:44:19.919Z
Updated: 2024-01-29T14:44:19.919Z
Reserved: 2024-01-02T12:00:34.810Z
Link: CVE-2023-7199
JSON object: View
NVD Information
Status : Analyzed
Published: 2024-01-29T15:15:09.897
Modified: 2024-02-03T00:24:17.240
Link: CVE-2023-7199
JSON object: View
Redhat Information
No data.
CWE