PT-2024-14841 · WordPress · Demomentsomtres Wordpress Export Posts With Images

Krzysztof Zając

·

Published

2024-01-15

·

Updated

2024-01-19

·

CVE-2023-5905

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions DeMomentSomTres WordPress Export Posts With Images WordPress plugin through 20220825
Description The issue allows any logged-in user, such as subscribers, to export the contents of the blog, including restricted and unpublished posts, as well as passwords of protected posts, due to a lack of authorization checks for requests to export blog data.
Recommendations For DeMomentSomTres WordPress Export Posts With Images WordPress plugin through 20220825, consider disabling the export functionality until a patch is available to prevent unauthorized access to blog data.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-5905

Affected Products

Demomentsomtres Wordpress Export Posts With Images