CVE-2023-6077 Information
Dec 22, 2023
cve
Description
The Slider WordPress plugin before 3.5.12 does not ensure that posts to be accessed via an AJAX action are slides and can be viewed by the user making the request allowing any authenticated users such as subscriber to access the content arbitrary post such as private draft and password protected
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Reference
https://wpscan.com/vulnerability/1afc0e4a-f712-47d4-bf29-7719ccbbbb1b
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
6.5
Share on: