PoC Index

CVE-2023-6289

MEDIUM 4.3EPSS 0.9%

The Swift Performance Lite WordPress plugin before 2.3.6.15 does not prevent users from exporting the plugin's settings, which may include sensitive information such as Cloudflare API tokens.

CVSS v3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
0.92% chance of exploitation in the next 30 days, 58th percentile
Published
2023-12-18
Updated
2025-05-07

Proof-of-concept exploits (2)

References

Related