{"api_version":"1","generated_at":"2026-07-23T11:22:50+00:00","cve":"CVE-2023-4836","urls":{"html":"https://cve.report/CVE-2023-4836","api":"https://cve.report/api/cve/CVE-2023-4836.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-4836","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-4836"},"summary":{"title":"CVE-2023-4836","description":"The WordPress File Sharing Plugin WordPress plugin before 2.0.5 does not check authorization before displaying files and folders, allowing users to gain access to those filed by manipulating IDs which can easily be brute forced","state":"PUBLIC","assigner":"contact@wpscan.com","published_at":"2023-10-31 14:15:00","updated_at":"2023-11-08 18:30:00"},"problem_types":["CWE-639"],"metrics":[],"references":[{"url":"https://research.cleantalk.org/cve-2023-4836-user-private-files-idor-to-sensitive-data-and-private-files-exposure-leak-of-info-poc","name":"https://research.cleantalk.org/cve-2023-4836-user-private-files-idor-to-sensitive-data-and-private-files-exposure-leak-of-info-poc","refsource":"MISC","tags":[],"title":"CVE-2023-4836 - User Private Files - IDOR to Sensitive data and private files exposure / leak of info - POC - Use only certified WordPress plugins for your website","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://wpscan.com/vulnerability/c17f2534-d791-4fe3-b45b-875777585dc6","name":"https://wpscan.com/vulnerability/c17f2534-d791-4fe3-b45b-875777585dc6","refsource":"MISC","tags":[],"title":"Just a moment...","mime":"text/html","httpstatus":"403","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-4836","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-4836","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"4836","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"userprivatefiles","cpe5":"wordpress_file_sharing_plugin","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-4836","ASSIGNER":"contact@wpscan.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"The WordPress File Sharing Plugin WordPress plugin before 2.0.5 does not check authorization before displaying files and folders, allowing users to gain access to those filed by manipulating IDs which can easily be brute forced"}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-639 Authorization Bypass Through User-Controlled Key"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Unknown","product":{"product_data":[{"product_name":"WordPress File Sharing Plugin","version":{"version_data":[{"version_affected":"<","version_name":"0","version_value":"2.0.5"}]}}]}}]}},"references":{"reference_data":[{"url":"https://wpscan.com/vulnerability/c17f2534-d791-4fe3-b45b-875777585dc6","refsource":"MISC","name":"https://wpscan.com/vulnerability/c17f2534-d791-4fe3-b45b-875777585dc6"},{"url":"https://research.cleantalk.org/cve-2023-4836-user-private-files-idor-to-sensitive-data-and-private-files-exposure-leak-of-info-poc","refsource":"MISC","name":"https://research.cleantalk.org/cve-2023-4836-user-private-files-idor-to-sensitive-data-and-private-files-exposure-leak-of-info-poc"}]},"generator":{"engine":"WPScan CVE Generator"},"source":{"discovery":"EXTERNAL"},"credits":[{"lang":"en","value":"Dmitrii Ignatyev"},{"lang":"en","value":"WPScan"}]},"nvd":{"publishedDate":"2023-10-31 14:15:00","lastModifiedDate":"2023-11-08 18:30:00","problem_types":["CWE-639"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:userprivatefiles:wordpress_file_sharing_plugin:*:*:*:*:*:wordpress:*:*","versionEndExcluding":"2.0.5","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}