CVE-2023-39999
⚪ Do wiadomości
Ujawnienie wrażliwych informacji w WordPress umożliwia nieautoryzowanym dostęp do danych.
CVSS
4.3
EPSS
1.0%
Exploit
poc
Vendor
wordpress
Opis źródłowy (NVD)
Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9, from 5.6 through 5.6.11, from 5.5 through 5.5.12, from 5.4 through 5.4.13, from 5.3 through 5.3.15, from 5.2 through 5.2.18, from 5.1 through 5.1.16, from 5.0 through 5.0.19, from 4.9 through 4.9.23, from 4.8 through 4.8.22, from 4.7 through 4.7.26, from 4.6 through 4.6.26, from 4.5 through 4.5.29, from 4.4 through 4.4.30, from 4.3 through 4.3.31, from 4.2 through 4.2.35, from 4.1 through 4.1.38.
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 4.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 1.0% |
| Opublikowano (NVD) | 2023-10-13 12:15:09 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-05 13:16:48 UTC |
Referencje
- https://lists.debian.org/debian-lts-announce/2023/11/msg00014.html ([email protected]) [Mailing List, Third Party Advisory]
- https://lists.fedoraproject.org/archives/list/[email protected]/message/2EVFT4DPZRFTXJPEPADM22BZVIUD2P66/ ([email protected]) [Mailing List, Third Party Advisory]
- https://lists.fedoraproject.org/archives/list/[email protected]/message/GCCVDPKOK57WCTH2QJ5DJM3B53RJNZKA/ ([email protected]) [Mailing List, Third Party Advisory]
- https://lists.fedoraproject.org/archives/list/[email protected]/message/WQBL4ZQCBFNQ76XHM5257CIBFQRGT5QY/ ([email protected]) [Mailing List, Third Party Advisory]
- https://patchstack.com/articles/wordpress-core-6-3-2-security-update-technical-advisory?_s_id=cve ([email protected]) [Exploit, Patch, Third Party Advisory]
- https://patchstack.com/database/vulnerability/wordpress/wordpress-wordpress-core-core-6-3-2-contributor-comment-read-on-private-and-password-protected-post-vulnerability?_s_id=cve ([email protected]) [Third Party Advisory]