PT-2024-15177 · WordPress · The Author Box

Krzysztof Zając

·

Published

2024-02-05

·

Updated

2024-02-15

·

CVE-2023-7014

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Author Box, Guest Author and Co-Authors for Your Posts – Molongui plugin for WordPress versions up to, and including, 4.7.4
Description The issue allows unauthenticated attackers to extract sensitive data, including post author emails and names, via the ma debu parameter. This makes it possible for attackers to access sensitive information without proper authentication.
Recommendations For versions up to, and including, 4.7.4, consider disabling the ma debu parameter to prevent sensitive information exposure until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

CVE-2023-7014

Affected Products

The Author Box