Vulnerabilities > Wordpress > Wordpress > 6.1.3

DATE CVE VULNERABILITY TITLE RISK
2023-10-16 CVE-2023-5561 Unspecified vulnerability in Wordpress
WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack
network
low complexity
wordpress
5.3
2023-10-13 CVE-2023-39999 Information Exposure vulnerability in multiple products
Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9, from 5.6 through 5.6.11, from 5.5 through 5.5.12, from 5.4 through 5.4.13, from 5.3 through 5.3.15, from 5.2 through 5.2.18, from 5.1 through 5.1.16, from 5.0 through 5.0.19, from 4.9 through 4.9.23, from 4.8 through 4.8.22, from 4.7 through 4.7.26, from 4.6 through 4.6.26, from 4.5 through 4.5.29, from 4.4 through 4.4.30, from 4.3 through 4.3.31, from 4.2 through 4.2.35, from 4.1 through 4.1.38.
network
low complexity
wordpress fedoraproject CWE-200
4.3
2023-10-13 CVE-2023-38000 Cross-site Scripting vulnerability in Wordpress Gutenberg and Wordpress
Auth.
network
low complexity
wordpress CWE-79
5.4