PT-2023-16593 · WordPress · Shortcodes Ultimate

Erwan Lr

·

Published

2023-03-20

·

Updated

2023-04-24

·

CVE-2023-0890

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Shortcodes Ultimate WordPress plugin versions prior to 5.12.8
Description The issue allows any authenticated users, such as subscribers, to view draft, private, or even password-protected posts. It is also possible to leak the password of protected posts. This occurs because the plugin does not ensure that posts to be displayed via some shortcodes are already public and can be accessed by the user making the request.
Recommendations For versions prior to 5.12.8, update to version 5.12.8 or later to resolve the issue. As a temporary workaround, consider restricting access to shortcodes that display posts to only authorized users until the update is applied.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-0890

Affected Products

Shortcodes Ultimate