VulnerabilityModified
CVE-2023-4836
The WordPress File Sharing Plugin WordPress plugin before 2.0.5 does not check authorization before displaying files and folders, allowing users to gain access to those filed by manipulating IDs which can easily be brute forced
MEDIUM 4.3EPSS 0.49%
Does this matter?
Lower severity and a low EPSS score (0.49%). Track it; it rarely justifies an emergency change on its own.
Description
The WordPress File Sharing Plugin WordPress plugin before 2.0.5 does not check authorization before displaying files and folders, allowing users to gain access to those filed by manipulating IDs which can easily be brute forced
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.49% probability · 41th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-639
- Affected
- userprivatefiles/wordpress file sharing plugin
- Source
- contact@wpscan.com
References
- https://research.cleantalk.org/cve-2023-4836-user-private-files-idor-to-sensitive-data-and-private-files-exposure-leak-of-info-pocExploit, Third Party Advisory
- https://wpscan.com/vulnerability/c17f2534-d791-4fe3-b45b-875777585dc6Exploit, Third Party Advisory
- https://research.cleantalk.org/cve-2023-4836-user-private-files-idor-to-sensitive-data-and-private-files-exposure-leak-of-info-pocExploit, Third Party Advisory
- https://wpscan.com/vulnerability/c17f2534-d791-4fe3-b45b-875777585dc6Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/c17f2534-d791-4fe3-b45b-875777585dc6Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.