CVE-2023-6731: WP Show Posts <= 1.1.5 - Improper Authorization to Information Exposure
The WP Show Posts plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple AJAX functions in all versions up to, and including, 1.1.5. This makes it possible for authenticated attackers, with subscriber access and above, to view arbitrary post metadata, list posts, and view terms and taxonomies.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6731?
CVE-2023-6731 has a medium severity rating due to the potential for unauthorized data access by authenticated attackers.
How do I fix CVE-2023-6731?
To fix CVE-2023-6731, update the WP Show Posts plugin to version 1.1.6 or later.
Who is affected by CVE-2023-6731?
CVE-2023-6731 affects users of the WP Show Posts plugin in WordPress versions up to and including 1.1.5.
What types of attacks are possible due to CVE-2023-6731?
Authenticated attackers with subscriber access and above can exploit CVE-2023-6731 to view arbitrary posts.
Is CVE-2023-6731 a plugin-specific vulnerability?
Yes, CVE-2023-6731 is specific to the WP Show Posts plugin for WordPress.