CVE-2023-3601

CVSS V2 None CVSS V3 None
Description
The Simple Author Box WordPress plugin before 2.52 does not verify a user ID before outputting information about that user, leading to arbitrary user information disclosure to users with a role as low as Contributor.
Overview
  • CVE ID
  • CVE-2023-3601
  • Assigner
  • contact@wpscan.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-08-14T20:15:11
  • Last Modified Date
  • 2023-08-21T16:05:15
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:webfactoryltd:simple_author_box:*:*:*:*:*:wordpress:*:* 1 OR 2.52
References
Reference URL Reference Tags
https://wpscan.com/vulnerability/c0cc513e-c306-4920-9afb-e33d95a7292f Exploit Third Party Advisory
History
Created Old Value New Value Data Type Notes
2023-09-06 03:43:33 Added to TrackCVE
2023-09-06 03:43:35 Weakness Enumeration new