ZeroHour

CVE-2023-4836

PoC ×2
CVSS 3.1
4.3 medium
EPSS
<1%p41
Published
()
Modified
Description

The WordPress File Sharing Plugin WordPress plugin before 2.0.5 does not check authorization before displaying files and folders, allowing users to gain access to those filed by manipulating IDs which can easily be brute forced

Vendors
userprivatefiles
Products
wordpress file sharing plugin
Ecosystems
WordPress
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.