First published: Mon Jan 29 2024(Updated: )
The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthenticated user to read draft and private posts via a crafted request
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Relevanssi | <=2.25.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-7199 has a medium severity rating as it allows unauthenticated users to access sensitive private content.
To fix CVE-2023-7199, you should update the Relevanssi plugin to version 4.22.0 or later for the free version, and version 2.25.0 or later for the premium version.
CVE-2023-7199 affects users of the Relevanssi WordPress plugin versions prior to 4.22.0 and Relevanssi Premium versions prior to 2.25.0.
CVE-2023-7199 allows access to draft and private posts by unauthenticated users.
The impact of CVE-2023-7199 is significant as it compromises the confidentiality of draft and private content, potentially exposing sensitive information.