PT-2023-17333 · WordPress · Blocksy Companion

Erwan Lr

·

Published

2023-05-02

·

Updated

2023-05-08

·

CVE-2023-1911

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Blocksy Companion WordPress plugin versions prior to 1.8.82
Description The issue allows any authenticated users, such as subscribers, to access draft posts via a shortcode, because it does not ensure that posts are already public and can be viewed.
Recommendations For versions prior to 1.8.82, update to version 1.8.82 or later to resolve the issue.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2023-1911

Affected Products

Blocksy Companion