plugin

Wp Private Message Vulnerabilities

2 known security issues reported for the Wp Private Message WordPress plugin. Most recent disclosed Feb 21, 2023.

1 high

Running Wp Private Message on your site? Check whether your installed version is affected.

Scan your site free

WP Private Message [wp-private-message] < 1.0.6

unknown

[en] The WP Private Message WordPress plugin (bundled with the Superio theme as a required plugin) before 1.0.6 does not ensure that private messages to be accessed belong to the user making the requests. This allowing any authenticated users to access private messages belonging to other users by tampering the ID.

Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
Feb 21, 2023

CVE-2023-0453 on NVD →

WP Private Message < 1.0.6 - Insecure Direct Object Reference

high

The WP Private Message plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and including, 1.0.6. This is due to insufficient validation on a user-controlled key identifying private messages between users. This makes it possible for authenticated attackers with subscriber-level capa...

CVSS:
7.1
Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
Jan 30, 2023

CVE-2023-0453 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database