CVE-2023-6257
MEDIUMDescription
The Inline Related Posts WordPress plugin before 3.6.0 is missing authorization in an AJAX action to ensure that users are allowed to see the content of the posts displayed, allowing any authenticated user, such as subscriber to retrieve the content of password protected posts
Is your site exposed to CVE-2023-6257?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| data443 | inline_related_posts |
References
Frequently Asked Questions
What is CVE-2023-6257? +
How severe is CVE-2023-6257? +
What products are affected by CVE-2023-6257? +
How do I check if I'm vulnerable to CVE-2023-6257? +
Related Vulnerabilities
The Inline Related Posts WordPress plugin before 3.7.0 does not sanitise and escape a parameter before outputting it back in …
The Tracking Code Manager WordPress plugin before 2.4.0 does not sanitise and escape some of its metabox settings when outputing …
The Inline Related Posts WordPress plugin before 3.8.0 does not sanitise and escape some of its settings, which could allow …
The Inline Related Posts WordPress plugin before 3.5.0 does not sanitise and escape some of its settings, which could allow …
The GDPR Framework By Data443 WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could …
The Tracking Code Manager WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could allow …