CVE-2024-0839

MEDIUM

FeedWordPress <2022.0222 - Info Disclosure

Title source: llm
STIX 2.1

Description

The FeedWordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2022.0222 due to missing validation on the user controlled 'guid' key. This makes it possible for unauthenticated attackers to view draft posts that may contain sensitive information.

Scores

CVSS v3 5.3
EPSS 0.0029
EPSS Percentile 52.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (2)
feedwordpress_project/feedwordpress < 2024.0428
radgeek/FeedWordPress < 2022.0222
Published Mar 13, 2024
Tracked Since Feb 18, 2026