SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-5561

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack

MEDIUM 5.3EPSS 3.86%

Does this matter?

Lower severity and a low EPSS score (3.86%). Track it; it rarely justifies an emergency change on its own.

Description

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
3.86% probability · 90th percentile
CISA KEV
Not listed
Affected
wordpress/wordpress
Source
contact@wpscan.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.