Source |
CVE Liste |
Identifiant |
8318158 |
Date de publication |
2023-03-13 17:15:12 (vue: 2023-03-13 19:07:12) |
Titre |
CVE-2023-0749 |
Texte |
The Ocean Extra WordPress plugin before 2.1.3 does not ensure that the template to be loaded via a shortcode is actually a template, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, such as draft, private or even password protected ones. |
Notes |
|
Envoyé |
Oui |
Condensat |
0749 2023 actually allowing any arbitrary authenticated before content cve does draft ensure even extra loaded not ocean ones password plugin posts private protected retrieve shortcode subscriber such template users wordpress |
Tags |
|
Stories |
APT 32
|
Move |
|