First published: Mon Feb 05 2024(Updated: )
The Author Box, Guest Author and Co-Authors for Your Posts – Molongui plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.4 via the 'ma_debu' parameter. This makes it possible for unauthenticated attackers to extract sensitive data including post author emails and names if applicable.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Amitzy Molongui | <4.7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-7014 has been classified as a high-severity vulnerability due to its potential for sensitive information exposure.
To fix CVE-2023-7014, update the Author Box, Guest Author, and Co-Authors for Your Posts – Molongui plugin to version 4.7.5 or later.
CVE-2023-7014 allows unauthorized attackers to extract sensitive data through the 'ma_debu' parameter.
All versions of the Molongui plugin for WordPress up to and including 4.7.4 are affected by CVE-2023-7014.
CVE-2023-7014 can be exploited by unauthenticated attackers, making it particularly dangerous.