Vulnerabilities > CVE-2023-4036 - Unspecified vulnerability in Riverforest-Wp Simple Blog Card

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
riverforest-wp

Summary

The Simple Blog Card WordPress plugin before 1.32 does not ensure that posts to be displayed via a shortcode are public, allowing any authenticated users, such as subscriber, to retrieve arbitrary post title and their content such as draft, private and password protected ones

Vulnerable Configurations

Part Description Count
Application
Riverforest-Wp
1