CVE-2023-6695: Beaver Themer <= 1.4.9 - Authenticated (Contributor+) Sensitive Information Exposure via shortcode
The Beaver Themer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the 'wpbb' shortcode. This makes it possible for authenticated attackers, with contributor access and above, to extract sensitive data including arbitrary usermeta values.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6695?
CVE-2023-6695 is classified as critical due to its ability to expose sensitive information to authenticated attackers.
How do I fix CVE-2023-6695?
To resolve CVE-2023-6695, update the Beaver Themer plugin to version 1.5.0 or later.
Who is affected by CVE-2023-6695?
Authenticated users with contributor access and above are affected by CVE-2023-6695.
What type of data can be exposed by CVE-2023-6695?
CVE-2023-6695 can expose sensitive data, including arbitrary user_meta information.
Which versions of the Beaver Themer plugin are vulnerable to CVE-2023-6695?
All versions of the Beaver Themer plugin up to and including 1.4.9 are vulnerable to CVE-2023-6695.