Co-Authors Plus 3.5 - 3.5.1 - Sensitive Information Disclosure
highThe Co-Authors Plus plugin for WordPress is vulnerable to sensitive information disclosure via the /wp/v2/coauthors REST API input in versions 3.5 and 3.5.1. This is due to insufficient capability checking that allows unauthorized users to access the endpoint and retrieve guest authors email addresses.
- CVSS:
- 7.5
- Affected:
- 3.5 – 3.5.1
- Fixed in:
- 3.5.2
- Disclosed:
- Jun 7, 2022