← Back to CVE List
WORDFENCE-b54af5b0-d79a-4fb2-965f-d3ff4956dc5aWordfence
Vulnerability Summary
WordPress Core is vulnerable to Information Exposure via the attachment_submitbox_metadata() function in various versions up to, and including, 7.1 due to a missing read_post capability check on an attachment's parent post. This makes it possible for authenticated attackers with upload_files access to view the title of a private or otherwise unreadable parent post to which an attachment is attached.
CVSS v3.1 Base Metrics — Score 4.3 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityLow
IntegrityNone
AvailabilityNone
Affected & Patched Versions
- WordPress * - 6.6.7
- WordPress 6.7 - 6.7.7
- WordPress 6.8 - 6.8.8
- WordPress 6.9 - 6.9.7
- WordPress 7.0 - 7.0.4
- WordPress 7.1 - 7.1
- WordPress 1