| CVE | CVE-2022-43504 |
|---|---|
| CVSS | Medium (5.3) |
| Publicly Published | October 18, 2022 |
| Last Updated | January 22, 2024 |
| Researcher |
Toshitsugu Yoneyama of Mitsui Bussan Secure Directions, Inc. via JPCERT
|
WordPress Core is vulnerable to Information Disclosure of in versions up to 6.0.3. When the post by email functionality is enabled, it may log post author's email addresses in a way that may be publicly accessible. This could make it possible for attackers to steal post author's email addresses and use that for further attacks.
References| Software Type | Core |
|---|---|
| Software Slug | wordpress (view on wordpress.org) |
| Patched? | Yes |
| Affected Version |
|
| Patched Version |
|
Copyright 2012-2026 Defiant Inc.
License: Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.
License Detail.