WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack
References
Link | Resource |
---|---|
https://lists.debian.org/debian-lts-announce/2023/11/msg00014.html | |
https://wpscan.com/blog/email-leak-oracle-vulnerability-addressed-in-wordpress-6-3-2/ | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/19380917-4c27-4095-abf1-eba6f913b441 | Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2023/11/msg00014.html | |
https://wpscan.com/blog/email-leak-oracle-vulnerability-addressed-in-wordpress-6-3-2/ | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/19380917-4c27-4095-abf1-eba6f913b441 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:42
Type | Values Removed | Values Added |
---|---|---|
References | () https://lists.debian.org/debian-lts-announce/2023/11/msg00014.html - | |
References | () https://wpscan.com/blog/email-leak-oracle-vulnerability-addressed-in-wordpress-6-3-2/ - Exploit, Third Party Advisory | |
References | () https://wpscan.com/vulnerability/19380917-4c27-4095-abf1-eba6f913b441 - Third Party Advisory |
20 Nov 2023, 23:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
08 Nov 2023, 19:15
Type | Values Removed | Values Added |
---|---|---|
Summary | WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack |
20 Oct 2023, 18:53
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-noinfo | |
References | (MISC) https://wpscan.com/vulnerability/19380917-4c27-4095-abf1-eba6f913b441 - Third Party Advisory | |
References | (MISC) https://wpscan.com/blog/email-leak-oracle-vulnerability-addressed-in-wordpress-6-3-2/ - Exploit, Third Party Advisory | |
First Time |
Wordpress wordpress
Wordpress |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
CPE | cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* |
16 Oct 2023, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-10-16 20:15
Updated : 2024-11-21 08:42
NVD link : CVE-2023-5561
Mitre link : CVE-2023-5561
CVE.ORG link : CVE-2023-5561
JSON object : View
Products Affected
wordpress
- wordpress
CWE