CVE-2023-5692

Published

Severity

CVSS v3:
N/A
CVSS v2:
N/A

Description

WordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.4.3 via the redirect_guess_404_permalink function. This can allow unauthenticated attackers to expose the slug of a custom post whose 'publicly_queryable' post status has been set to 'false'.

References

Configurations

CPE23Version StartVersion EndExact Version

External Links