PT-2024-14827 · WordPress+1 · Wordpress+1

Francesco Carlucci

·

Published

2024-04-05

·

Updated

2024-04-09

·

CVE-2023-5692

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WordPress Core versions up to, and including, 6.4.3
Description The issue allows unauthenticated attackers to expose the slug of a custom post whose publicly queryable post status has been set to 'false' via the redirect guess 404 permalink function.
Recommendations For versions up to, and including, 6.4.3, update to a version later than 6.4.3 to resolve the issue. As a temporary workaround, consider restricting access to custom posts with publicly queryable set to 'false' until a patch is available.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BIT-WORDPRESS-2023-5692
BIT-WORDPRESS-MULTISITE-2023-5692
CVE-2023-5692

Affected Products

Debian
Wordpress