CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.3. It affects WordPress. Exploitation may require the attacker to be authenticated.
CVE
CVE-2023-1911
Severity
MEDIUM
CVSS
4.3
EPSS
0.55%
WordPress
Original NVD Description
The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are already public and can be viewed, allowing any authenticated users, such as subscriber to access draft posts for example
Related CVEs
Other vulnerabilities affecting the same vendor(s)