Vulnerabilities > CVE-2023-1371 - Missing Authorization vulnerability in W4 Post List Project W4 Post List

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
w4-post-list-project
CWE-862

Summary

The W4 Post List WordPress plugin before 2.4.6 does not ensure that password protected posts can be accessed before displaying their content, which could allow any authenticated users to access them

Vulnerable Configurations

Part Description Count
Application
W4_Post_List_Project
101

Common Weakness Enumeration (CWE)