CVE-2023-1911: Blocksy Companion < 1.8.82 - Subscriber+ Draft Post Access
The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are already public and can be viewed, allowing any authenticated users, such as subscriber to access draft posts for example
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-1911?
CVE-2023-1911 is considered a medium severity vulnerability due to its potential to expose sensitive draft posts to unauthorized authenticated users.
How do I fix CVE-2023-1911?
To fix CVE-2023-1911, update the Blocksy Companion plugin to version 1.8.82 or later.
What systems are affected by CVE-2023-1911?
CVE-2023-1911 affects Blocksy Companion WordPress plugin versions prior to 1.8.82.
What type of access does CVE-2023-1911 allow?
CVE-2023-1911 allows any authenticated users, including subscribers, to access private draft posts that should be restricted.
Who is primarily at risk from CVE-2023-1911?
Users with lower permission levels, such as subscribers, are primarily at risk from CVE-2023-1911 due to unauthorized access to draft posts.