PT-2024-15177 · WordPress · The Author Box
Krzysztof Zając
·
Published
2024-02-05
·
Updated
2024-02-15
·
CVE-2023-7014
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
The Author Box, Guest Author and Co-Authors for Your Posts – Molongui plugin for WordPress versions up to, and including, 4.7.4
Description
The issue allows unauthenticated attackers to extract sensitive data, including post author emails and names, via the
ma debu parameter. This makes it possible for attackers to access sensitive information without proper authentication.Recommendations
For versions up to, and including, 4.7.4, consider disabling the
ma debu parameter to prevent sensitive information exposure until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
The Author Box