CVE-2023-6257: Inline Related Posts < 3.6.0 - Subscriber+ Password Protected Post Read
The Inline Related Posts WordPress plugin before 3.6.0 is missing authorization in an AJAX action to ensure that users are allowed to see the content of the posts displayed, allowing any authenticated user, such as subscriber to retrieve the content of password protected posts
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6257?
CVE-2023-6257 has been classified with a medium severity due to the potential exposure of sensitive content.
How do I fix CVE-2023-6257?
To fix CVE-2023-6257, update the Inline Related Posts WordPress plugin to version 3.6.0 or later.
Who is affected by CVE-2023-6257?
Authenticated users, including subscribers, are affected by CVE-2023-6257 as they can access password-protected post content.
What type of vulnerability is CVE-2023-6257?
CVE-2023-6257 is an authorization vulnerability in an AJAX action of the Inline Related Posts plugin.
Is there a workaround for CVE-2023-6257?
There are no specific workarounds available for CVE-2023-6257 besides updating to the patched version.