QID 731066

QID 731066: WordPress Email ID Information Disclosure Vulnerability

WordPress is software designed for everyone, emphasizing accessibility, performance, security, and ease of use.

CVE-2023-5561: Vulnerable to Email ID Information Disclosure vulnerability using Brute-force technique.

Affected Versions:
WordPress versions form 4.7 prior to 6.3.2

QID Detection Logic:
The QID issues a GET request using a wildcard (@) and verifies the POC by inspecting the target.

Successful exploitation of this vulnerability may disclose Email information of the author.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to upgrade to the fixed versions 6.3.2 to remediate these vulnerabilities:
    For more Information Please visit WordPress site

    CVEs related to QID 731066

    Software Advisories
    Advisory ID Software Component Link
    Wordpress 6.3.2 URL Logo wordpress.org/news/2023/10/wordpress-6-3-2-maintenance-and-security-release/