WP Private Message [wp-private-message] < 1.0.6
unknown
[en] The WP Private Message WordPress plugin (bundled with the Superio theme as a required plugin) before 1.0.6 does not ensure that private messages to be accessed belong to the user making the requests. This allowing any authenticated users to access private messages belonging to other users by tampering the ID.
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Feb 21, 2023
CVE-2023-0453 on NVD →
WP Private Message < 1.0.6 - Insecure Direct Object Reference
high
The WP Private Message plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and including, 1.0.6. This is due to insufficient validation on a user-controlled key identifying private messages between users. This makes it possible for authenticated attackers with subscriber-level capa...
- CVSS:
- 7.1
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Jan 30, 2023
CVE-2023-0453 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database