CVE-2024-1564
EUVD-2024-1730825.03.2024, 05:15
The wp-schema-pro WordPress plugin before 2.7.16 does not validate post access allowing a contributor user to access custom fields on any post regardless of post type or status via a shortcodeEnginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| wpschema | wpschema_pro | 𝑥 < 2.7.16 |
| brainstormforce | schema | 𝑥 < 2.7.16 |
𝑥
= Vulnerable software versions