CVE-2023-1911
02.05.2023, 08:15
The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are already public and can be viewed, allowing any authenticated users, such as subscriber to access draft posts for exampleEnginsight
Vendor | Product | Version |
---|---|---|
creativethemes | blocksy_companion | 𝑥 < 1.8.82 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration