CVE-2023-0453
Summary
| CVE | CVE-2023-0453 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-21 09:15:00 UTC |
| Updated | 2023-11-07 04:00:00 UTC |
| Description | The WP Private Message WordPress plugin (bundled with the Superio theme as a required plugin) before 1.0.6 does not ensure that private messages to be accessed belong to the user making the requests. This allowing any authenticated users to access private messages belonging to other users by tampering the ID. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| WP Private Message < 1.0.6 - Private Message Disclosure via IDOR WordPress Security Vulnerability |
MISC |
wpscan.com |
|
| Superio – Job Board WordPress Theme by ApusTheme | ThemeForest |
MISC |
themeforest.net |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.