CVE-2023-3371: EmbedPress <= 3.7.3 - Sensitive Information Exposure
The EmbedPress plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'lockcontentformhandler' and 'displaypasswordform' function in versions up to, and including, 3.7.3. This makes it possible for unauthenticated attackers to decrypt and view the password protected content.
Other sources
The User Registration plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'lockcontentformhandler' and 'displaypasswordform' function in versions up to, and including, 3.7.3. This makes it possible for unauthenticated attackers to decrypt and view the password protected content.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
EmbedPressto a version that resolves this vulnerability.Fixed in 3.7.3 - Upgrade
Upgrade
User Registrationto a version that resolves this vulnerability.Fixed in 3.7.3
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2023-3371.
What is the severity of CVE-2023-3371?
The severity of CVE-2023-3371 is high with a score of 7.5.
What is the affected software of CVE-2023-3371?
The affected software of CVE-2023-3371 is the User Registration plugin for WordPress up to and including version 3.7.3.
What is the description of CVE-2023-3371?
CVE-2023-3371 is a vulnerability in the User Registration plugin for WordPress that allows unauthenticated attackers to decrypt sensitive information due to a hardcoded encryption key.
Is there a fix available for CVE-2023-3371?
Yes, updating the User Registration plugin for WordPress to a version higher than 3.7.3 will fix the vulnerability.