PoC Index

CVE-2023-3706

MEDIUM 4.3EPSS 0.5%

The ActivityPub WordPress plugin before 1.0.0 does not ensure that post titles to be displayed are public and belong to the plugin, allowing any authenticated user, such as subscriber to retrieve the title of arbitrary post (such as draft and private) via an IDOR vector

CVSS v3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
0.47% chance of exploitation in the next 30 days, 39th percentile
Published
2023-10-16
Updated
2025-04-23

Proof-of-concept exploits (1)

References

Related