plugin

Co Authors Plus Vulnerabilities

1 known security issue reported for the Co Authors Plus WordPress plugin. Most recent disclosed Jun 7, 2022.

1 high

Running Co Authors Plus on your site? Check whether your installed version is affected.

Scan your site free

Co-Authors Plus 3.5 - 3.5.1 - Sensitive Information Disclosure

high

The Co-Authors Plus plugin for WordPress is vulnerable to sensitive information disclosure via the /wp/v2/coauthors REST API input in versions 3.5 and 3.5.1. This is due to insufficient capability checking that allows unauthorized users to access the endpoint and retrieve guest authors email addresses.

CVSS:
7.5
Affected:
3.5 – 3.5.1
Fixed in:
3.5.2
Disclosed:
Jun 7, 2022

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database