CVE-2023-7199: Relevanssi (Free < 4.22.0, Premium < 2.25.0) - Unauthenticated Private/Draft Post Disclosure
The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthenticated user to read draft and private posts via a crafted request
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7199?
CVE-2023-7199 has a medium severity rating as it allows unauthenticated users to access sensitive private content.
How do I fix CVE-2023-7199?
To fix CVE-2023-7199, you should update the Relevanssi plugin to version 4.22.0 or later for the free version, and version 2.25.0 or later for the premium version.
Who is affected by CVE-2023-7199?
CVE-2023-7199 affects users of the Relevanssi WordPress plugin versions prior to 4.22.0 and Relevanssi Premium versions prior to 2.25.0.
What types of posts can be accessed due to CVE-2023-7199?
CVE-2023-7199 allows access to draft and private posts by unauthenticated users.
What is the impact of CVE-2023-7199 on website security?
The impact of CVE-2023-7199 is significant as it compromises the confidentiality of draft and private content, potentially exposing sensitive information.